Home › Topics › automated decision-making
U.S. AI Laws: automated decision-making
As of 2026-08-12, AI Laws USA tracks 522 U.S. AI rules on automated decision-making across federal, state, county, and city government. Each entry links to its official source.
Federal automated decision-making rules (100)
-
In effect
Benavides v. Tesla (Autopilot)
S.D. Fla. · Effective 2025-08-01 · Benavides v. Tesla, Inc., No. 1:21-cv-21940 (S.D. Fla. Aug. 1, 2025)
A Florida federal jury found Tesla 33% liable in August 2025 for the 2019 death of Naibel Benavides Leon, in a crash involving Autopilot. The jury awarded $243M ($129M compensatory + $200M punitive); in February 2026 the court denied Tesla's post-trial motions and upheld the verdict in full — the first Autopilot wrongful-death verdict against Tesla.
-
Blocked / in litigation
NetChoice v. Yost (Ohio)
S.D. Ohio · Effective 2025-04-16 · NetChoice, LLC v. Yost, No. 2:24-cv-00047 (S.D. Ohio Apr. 16, 2025)
Ohio's Social Media Parental Notification Act — requiring parental consent for minors' social-media use, including algorithmic feeds — was preliminarily enjoined on February 12, 2024, then permanently enjoined on April 16, 2025 when the district court granted summary judgment for NetChoice. The state appealed to the Sixth Circuit, which vacated the district court's injunction in 2026.
-
In effect
Louis v. SafeRent
D. Mass. · Effective 2024-11-20 · Louis v. SafeRent Solutions, LLC, No. 1:22-cv-10800 (D. Mass.)
SafeRent agreed in November 2024 to a $2.275M settlement and a five-year ban on using its 'SafeRent Score' for housing-voucher applicants, after a class action alleged its AI tenant-screening tool systematically denied housing to Black and Hispanic Section 8 voucher holders. The first major AI tenant-screening Fair Housing Act settlement.
-
In effect
EEOC v. iTutorGroup
E.D.N.Y. · Effective 2023-09-11 · EEOC v. iTutorGroup, Inc., No. 1:22-cv-02565 (E.D.N.Y. Sept. 11, 2023)
The EEOC's first AI-hiring-discrimination case ended with a $365,000 consent decree in September 2023. iTutorGroup's online application system was programmed to auto-reject female applicants 55+ and male applicants 60+ — a clear ADEA violation through algorithmic age screening.
-
In effect
Thaler v. Vidal (DABUS)
Fed. Cir. · Effective 2022-08-05 · Thaler v. Vidal, 43 F.4th 1207 (Fed. Cir. 2022), cert. denied, 143 S. Ct. 1783 (2023)
Stephen Thaler, inventor of the 'DABUS' AI system, sought to list DABUS as the inventor on two patent applications. The Federal Circuit ruled in August 2022 that under the Patent Act 'inventor' must be a natural person. The Supreme Court denied certiorari in April 2023, settling U.S. law: AI systems cannot be inventors of record.
-
In effect
ECOA / Regulation B (AI credit discrimination)
United States · Effective 1975-10-28 · 15 U.S.C. § 1691; 12 C.F.R. Part 1002
Lenders cannot discriminate in credit decisions and must give you specific, accurate reasons when they deny or worsen your credit — even if the decision was made by an AI model. Earlier CFPB guidance said lenders can't hide behind 'black box' algorithms; that guidance was withdrawn in May 2025, but the underlying statute and regulation still require accurate adverse-action notices.
-
In effect
FCRA (AI in credit & background checks)
United States · Effective 1971-04-25 · 15 U.S.C. § 1681 et seq.
When a company uses a consumer report or score — including AI-generated risk scores from background-check and tenant/employment screening firms — to deny you credit, insurance, housing, or a job, it must tell you and identify the agency that supplied the report. You have the right to a free copy of your file and to dispute inaccurate information, no matter how algorithmic the scoring was.
-
In effect
Title VII / ADA (AI hiring)
United States · Effective 1965-07-02 · 42 U.S.C. § 2000e et seq.; 42 U.S.C. § 12101 et seq.
Federal anti-discrimination law applies when employers use AI tools to screen resumes, score interviews, or rank candidates: if an AI tool disproportionately screens out people by race, sex, disability, or other protected traits, the employer can be liable. The EEOC's specific AI guidance documents from 2023 were removed in January 2025, but the underlying laws are unchanged and still enforceable.
-
In effect
FTC Act Section 5 (unfair/deceptive AI)
United States · Effective 1914-09-26 · 15 U.S.C. § 45
The FTC's basic consumer-protection law bans unfair or deceptive business practices, and the agency applies it directly to AI. Companies cannot lie about what their AI can do, use AI to deceive people, or sell AI tools designed for fraud. The FTC's 'Operation AI Comply' sweep has brought numerous cases since 2024.
-
In effect
Meta AI Layoff Discrimination Lawsuit (2026)
United States · Effective 2026-07-15 · 26 Meta employees v. Meta Platforms, Inc., N.D. Cal. (Oakland), filed July 15, 2026; FMLA, ADA, PDA, PWFA claims
Twenty-six current and former Meta employees filed a lawsuit on July 15, 2026 in the Northern District of California (Oakland) alleging that Meta's internal AI system called 'Metamate' was used to select workers for layoffs in a way that disproportionately targeted employees on medical leave, pregnancy leave, and parental leave. The plaintiffs allege violations of the Family and Medical Leave Act (FMLA), the Americans with Disabilities Act (ADA), the Pregnancy Discrimination Act, and the Pregnant Workers Fairness Act. The court denied an emergency injunction request on July 17, 2026. The case represents a significant test of employer liability when an AI system makes or influences employment termination decisions affecting workers with protected characteristics.
-
In effect
DOJ-RealPage Consent Decree (algorithmic rent)
United States · Effective 2026-05-01 · United States v. RealPage, Inc. et al., No. 1:24-cv-00710 (M.D.N.C.); 15 U.S.C. §§ 1–2
In November 2025, the DOJ settled with RealPage — the dominant algorithmic rent-pricing software company — requiring it to stop using competitors' real-time pricing data to coordinate rents. The settlement received preliminary court approval in May 2026 and places RealPage under a court-appointed compliance monitor for seven years. Thousands of property managers used RealPage's software; the DOJ alleged it enabled competing landlords to align rental prices, harming renters across the country.
-
In effect
Kistler v. Eightfold AI (FCRA, AI hiring)
United States · Effective 2026-01-20 · Kistler et al. v. Eightfold AI Inc., Case 3:26-cv-1768 (N.D. Cal.); 15 U.S.C. § 1681 et seq. (FCRA)
Erin Kistler and Sruti Bhaumik filed a class action in California Superior Court in January 2026 (later removed to federal court as Case 3:26-cv-1768 in the Northern District of California) against Eightfold AI, a leading AI hiring platform. The plaintiffs allege that Eightfold scraped over one billion worker profiles and used an AI model to rank job applicants on a scale of 0 to 5 without providing the disclosures and adverse action notices required by the Fair Credit Reporting Act (FCRA). The case targets AI hiring tools that function as employment screening reports, arguing that the FCRA's consumer-report protections extend to AI-driven applicant scoring systems. A motion to dismiss is set for hearing on August 4, 2026 before Judge Yvonne Gonzalez Rogers.
-
In effect
OMB M-25-21
United States · Effective 2025-04-03 · OMB Memo M-25-21 (Apr. 3, 2025)
OMB Memorandum M-25-21 (Apr. 3, 2025) is the Trump-era replacement for M-24-10. It sets the binding rule for how federal agencies use AI — requiring CAIO designations, AI use inventories, and risk-management practices for rights/safety-impacting AI, with a pro-innovation framing.
-
Blocked / in litigation
NetChoice v. Bonta (SB 976)
N.D. Cal. · Effective 2024-12-31 · NetChoice, LLC v. Bonta, No. 5:24-cv-07885 (N.D. Cal.)
NetChoice (the tech-industry trade group) challenged California's SB 976 — which would have restricted addictive algorithmic feeds for minors — and won a preliminary injunction blocking key portions on First Amendment grounds in December 2024. The 9th Circuit is reviewing.
-
In effect
FDA PCCP Guidance (AI/ML devices)
United States · Effective 2024-12-04 · FDA Guidance (Dec. 4, 2024); 21 U.S.C. § 360e-4
FDA finalized a framework that lets manufacturers update an AI-enabled medical device after clearance without filing a new submission for each change — but only if they pre-specify what changes are allowed, how they'll be validated, and how transparency to clinicians and patients will be preserved.
-
In effect
CFPB AI chatbot circular
United States · Effective 2024-10-23 · CFPB Issue Spotlight (June 2023); CFPB UDAAP / ECOA / TILA enforcement posture (2024)
Building on its 2023 chatbot report, the CFPB has warned that banks and lenders using generative-AI chatbots that mislead consumers — about fees, account terms, or credit denials — face liability under the Consumer Financial Protection Act, the Equal Credit Opportunity Act, and the Truth in Lending Act. Hallucinating chatbots are not a regulatory loophole.
-
Blocked / in litigation
Character.AI Companion Chatbot Suits
M.D. Fla. + E.D. Tex. · Effective 2024-10-22 · Garcia v. Character Techs., Inc., No. 6:24-cv-01903 (M.D. Fla.); A.F. v. Character Techs., Inc., No. 2:24-cv-01014 (E.D. Tex.)
Five plaintiffs across two jurisdictions sued Character.AI in 2024 alleging the companion chatbot service caused minors' suicide, self-harm, sexual abuse, and severe mental injury. Garcia v. Character.AI in Florida was the first AI companion wrongful-death suit; in Texas a federal court issued a landmark May 2025 ruling that AI chatbot outputs are not protected First Amendment speech.
-
In effect
FTC Operation AI Comply
United States · Effective 2024-09-25 · FTC Operation AI Comply (Sept. 25, 2024)
FTC enforcement sweep announcing five settlements against firms using AI to enable deceptive or unfair conduct. Establishes a baseline of cases for ongoing AI deception enforcement.
-
In effect
FTC v. DoNotPay
FTC · Effective 2024-09-25 · In re DoNotPay, Inc., FTC No. C-4796 (Sept. 25, 2024)
The FTC settled with 'AI lawyer' DoNotPay in September 2024 over claims the company falsely marketed an AI chatbot as a substitute for a human lawyer, without ever testing whether its outputs matched a competent attorney's work. Part of the FTC's 'Operation AI Comply' sweep.
-
In effect
DOJ AI-fraud sentencing guidance
United States · Effective 2024-09-23 · DOJ Criminal Division ECCP (Sept. 23, 2024); Deputy AG Lisa Monaco, ABA White Collar Conf. (Mar. 5, 2024)
The Justice Department updated its corporate compliance guidance in September 2024 to require companies to assess and mitigate AI-related risks, and Deputy AG Lisa Monaco announced in March 2024 that DOJ will seek stiffer sentences when AI is used to commit fraud — treating AI as an aggravating factor.
-
Blocked / in litigation
CCIA v. Paxton (TX SCOPE)
W.D. Tex. · Effective 2024-08-30 · CCIA v. Paxton, No. 1:24-cv-00849 (W.D. Tex.)
The Computer & Communications Industry Association and NetChoice partially enjoined Texas's SCOPE Act (HB 18), which restricts targeted advertising and algorithmic content curation for minors, before its September 2024 effective date.
-
In effect
HHS § 1557 Rule (AI clinical tools)
United States · Effective 2024-07-05 · 45 C.F.R. § 92.210; 89 Fed. Reg. 37522
HHS's Section 1557 rule bans discrimination in 'patient care decision-support tools,' which includes AI and algorithmic clinical tools. Covered health programs and providers must identify when a tool relies on patient race, age, disability, or other protected traits and take steps to mitigate the risk of discrimination.
-
In effect
HUD FHEO Tenant Screening AI
United States · Effective 2024-05-02 · HUD FHEO, Guidance on Application of the Fair Housing Act to the Screening of Applicants for Rental Housing (May 2, 2024)
HUD guidance applying the Fair Housing Act to algorithmic tenant screening — landlords and screening vendors share liability for discriminatory outcomes.
-
In effect
HUD FHEO Digital Advertising AI
United States · Effective 2024-05-02 · HUD FHEO, Guidance on Application of the Fair Housing Act to the Advertising of Housing, Credit, and Other Real Estate-Related Transactions through Digital Platforms (May 2, 2024)
HUD guidance making clear that algorithmic ad-targeting causing discriminatory exposure violates the Fair Housing Act.
-
In effect
OFCCP AI Selection Guidance
United States · Effective 2024-04-29 · OFCCP AI EEO Guidance (Apr. 29, 2024)
Federal contractors using AI in hiring must comply with OFCCP nondiscrimination requirements: vendor due diligence, recordkeeping, validation under the Uniform Guidelines on Employee Selection Procedures, and accommodations for applicants with disabilities. OFCCP makes clear contractors cannot outsource liability to AI vendors.
-
In effect
DOL WHD FAB 2024-1
United States · Effective 2024-04-29 · DOL WHD FAB 2024-1 (Apr. 29, 2024)
DOL Wage and Hour Division guidance on FLSA, FMLA, PUMP Act, and EPPA compliance when employers use AI for scheduling, timekeeping, monitoring, or performance evaluation.
-
In effect
SEC AI-washing settlement
United States · Effective 2024-03-18 · In re Delphia (USA) Inc., Securities Act Rel. No. 11264 (Mar. 18, 2024); In re Global Predictions Inc., Securities Act Rel. No. 11265 (Mar. 18, 2024)
The SEC charged two investment advisers — Delphia (USA) and Global Predictions — with making false and misleading statements about using AI and machine learning. The firms paid $400,000 combined in civil penalties. It was the SEC's first 'AI-washing' enforcement action and signals scrutiny of overstated AI capability claims in financial services.
-
In effect
DOJ/HUD Statement of Interest (algorithmic rent)
DOJ / HUD · Effective 2024-03-01 · Statement of Interest of the United States, McKenna Duffy v. Yardi Systems, Inc., et al., W.D. Wash. (Mar. 2024)
The Justice Department's Antitrust Division and the FTC (not HUD) filed a joint Statement of Interest in Duffy v. Yardi Systems (W.D. Wash.), arguing that competing landlords' joint use of Yardi's common pricing algorithm can constitute per-se illegal price fixing under the Sherman Act, even when landlords retain some discretion to deviate from the algorithm's recommendations.
-
In effect
CMS MA Rule (AI prior auth)
United States · Effective 2024-01-01 · 42 C.F.R. § 422.101(c); 88 Fed. Reg. 22120 (Apr. 12, 2023)
Medicare Advantage plans cannot use algorithms or AI to deny medically necessary care. Any algorithm-driven coverage decision must comply with traditional Medicare coverage criteria and consider the individual patient's circumstances — not just generic model output.
-
Blocked / in litigation
DOJ / Multistate v. Yardi
W.D. Wash. · Effective 2023-12-29 · Duffy v. Yardi Systems, Inc., No. 2:23-cv-01391 (W.D. Wash.)
Renters brought a parallel class action against Yardi Systems — RealPage's main competitor in algorithmic rent-pricing — alleging it likewise coordinated multifamily rents across competing landlords. State AGs joined as enforcement actors; the case is moving in parallel with the DOJ-RealPage proceeding.
-
Blocked / in litigation
Lokken v. UnitedHealth (nH Predict)
D. Minn. · Effective 2023-11-14 · Estate of Lokken v. UnitedHealth Group, Inc., No. 0:23-cv-03514 (D. Minn.)
Families of deceased Medicare Advantage patients sued UnitedHealth in November 2023 over the 'nH Predict' algorithm, alleging the AI tool overrode physicians and prematurely terminated post-acute care coverage with an error rate above 90 percent in appeals — accelerating patient harms and deaths. On March 9, 2026, the court issued a significant discovery order compelling UnitedHealth to produce broad documentation of the nH Predict algorithm, including training data, model documentation, and internal performance audits.
-
In effect
VA Trustworthy AI Framework
United States · Effective 2023-09-22 · VA Directive 1003.2; VA AI Strategy (Sept. 2023)
The VA's Trustworthy AI Framework governs how AI may be used across VA healthcare, benefits, and operations. AI used in benefits or clinical decisions requires human review, bias testing, and an AI use-case inventory submitted to OMB.
-
In effect
CFPB Circ. 2023-03 (AI credit)
United States · Effective 2023-09-19 · CFPB Circular 2023-03 (Sept. 19, 2023)
CFPB Circular 2023-03 clarifies that lenders using AI or other complex credit models for credit denial cannot rely on checklist adverse-action notices. They must provide specific, accurate reasons under ECOA — even if the AI's decision is hard to explain.
-
In effect
CFPB § 1071 Rule (small-biz AI lending)
United States · Effective 2023-08-29 · 12 C.F.R. Part 1002 Subpart B; 88 Fed. Reg. 35150
Lenders covered by the rule must collect and report demographic and transactional data on small-business credit applications — including data needed to detect algorithmic discrimination by AI underwriting models.
-
Blocked / in litigation
Cigna PXDX AI Denial Class Action
E.D. Cal. · Effective 2023-07-24 · Kisting-Leung v. Cigna Corp., No. 2:23-cv-01477 (E.D. Cal.)
Patients sued Cigna in 2023 alleging its 'PxDx' algorithm reviewed and denied roughly 300,000 claims in two months — averaging 1.2 seconds per denial — without genuine physician review, violating California and federal law. Triggered a wave of similar AI healthcare-denial suits against UnitedHealth (NaviHealth) and Humana.
-
In effect
Mata v. Avianca (ChatGPT fake cites)
S.D.N.Y. · Effective 2023-06-22 · Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023)
Two New York attorneys submitted a brief containing six fictitious case citations generated by ChatGPT. In June 2023 Judge P. Kevin Castel sanctioned them $5,000 each — the first formal federal sanction for AI-hallucinated legal citations, and the most-cited case in subsequent bar opinions on attorney AI use.
-
In effect
EEOC AI Title VII Guidance
United States · Effective 2023-05-18 · EEOC TA (May 18, 2023)
EEOC guidance applying Title VII disparate-impact analysis to AI hiring tools. Employers are liable for discriminatory outcomes even when the tool is built by a vendor.
-
In effect
DoD Directive 3000.09 (LAWS)
United States · Effective 2023-01-25 · DoDD 3000.09 (2023)
The Defense Department's policy on autonomous and semi-autonomous weapons. Updated in January 2023, it requires every autonomous or semi-autonomous weapon system to allow 'appropriate levels of human judgment over the use of force,' undergo a multi-phase senior review before development and fielding, and comply with DoD AI ethical principles.
-
Blocked / in litigation
Huskey v. State Farm
N.D. Ill. · Effective 2022-12-14 · Huskey v. State Farm Fire & Cas. Co., No. 1:22-cv-07014 (N.D. Ill.)
Black homeowners sued State Farm in 2022, alleging the insurer's claims-handling AI subjected them to greater scrutiny — more documentation requests, more delays, and higher denial rates — than white homeowners. One of the leading insurance-AI disparate-treatment cases.
-
In effect
FDA GMLP Principles
United States · Effective 2021-10-27 · FDA/HC/MHRA GMLP Guiding Principles (Oct. 27, 2021)
Joint guiding principles by FDA, Health Canada, and the UK MHRA on safe development of ML-enabled medical devices. Updated by FDA's 2024 Transparency Guiding Principles.
-
In effect
NHTSA SGO 2021-01 (AV/ADAS reporting)
United States · Effective 2021-06-29 · NHTSA SGO 2021-01
Manufacturers and operators of vehicles equipped with SAE Level 2 driver-assistance (Tesla Autopilot, GM Super Cruise) or Level 3-5 automated driving systems must report crashes to NHTSA on a strict timeline — within one day for serious crashes. The data drives recall actions including Tesla's Dec. 2023 over-the-air Autopilot recall.
-
In effect
NHTSA AV federal framework
United States · Effective 2021-06-29 · NHTSA Standing General Order 2021-01; 49 U.S.C. § 30166
NHTSA's Standing General Order requires automakers and operators of Level 2 driver-assistance and Level 3–5 automated driving systems to report crashes involving those systems. Federal Motor Vehicle Safety Standards regulate vehicle design; NHTSA's voluntary safety guidance (AV 4.0) and the Automated Vehicle Comprehensive Plan provide non-binding policy direction.
-
In effect
FDA AI/ML SaMD Action Plan
United States · Effective 2021-01-12 · FDA AI/ML SaMD Action Plan (Jan. 12, 2021)
FDA's 5-part roadmap for regulating AI/ML-based Software as a Medical Device, including a proposed Predetermined Change Control Plan framework that lets developers update models without full FDA re-review.
-
In effect
FDA 510(k) — surgical robots
United States · Effective 1976-05-28 · 21 U.S.C. § 360(k); 21 C.F.R. Part 807
Robotically-assisted surgical devices (RASD) — like Intuitive's da Vinci or Stryker's Mako — are FDA-regulated medical devices. Most clear the market through the 510(k) pathway by showing substantial equivalence to a predicate device. The FDA issued a 2019 safety communication and continues to police off-label robotic mastectomy and AI-software updates under its evolving 'Predetermined Change Control Plan' authority.
-
In effect
Trump AI Innovation & Security EO (June 2026)
United States · Effective 2026-06-02 · E.O. (June 2, 2026) — Promoting Advanced Artificial Intelligence Innovation and Security
President Trump signed an executive order on June 2, 2026, directing frontier AI developers to voluntarily share new models with the federal government 30 days before public release for national-security review. The order also directs CISA to build an AI cybersecurity framework and tasks DOJ with prioritizing criminal enforcement of AI-enabled fraud. No binding requirements apply to private AI developers — the framework is voluntary.
-
Blocked / in litigation
Florida AG v. OpenAI (AI safety, minors)
United States · Effective 2026-06-01 · State of Florida ex rel. Uthmeier v. OpenAI LLC et al. (Highlands County 10th Jud. Cir., June 1, 2026; removed to S.D. Fla. July 2, 2026)
Florida Attorney General James Uthmeier filed the first-in-nation state-led lawsuit against OpenAI on June 1, 2026, in Highlands County Circuit Court, alleging ChatGPT was deceptively marketed to minors despite known safety risks. The 10-count complaint cites specific harms including the death of 16-year-old Adam Raine, who died by suicide following extensive ChatGPT conversations, and the alleged use of ChatGPT by the accused Florida State University mass shooter. OpenAI LLC and CEO Sam Altman (named personally) removed the case to federal court before Judge Aileen Cannon in Fort Pierce on July 2, 2026. Florida has moved to remand; the jurisdictional battle is ongoing.
-
Proposed / pending
NAIC AI Evaluation Tool Pilot (12 states, 2026)
United States · Effective 2026-03-02 · NAIC Big Data and AI (H) Working Group — AI Systems Evaluation Tool Pilot (launched March 2, 2026)
The National Association of Insurance Commissioners launched a 12-state pilot program in March 2026 to test a new 'AI Systems Evaluation Tool' — a standardized framework giving insurance examiners a structured method to assess how insurance companies govern their AI systems during market conduct and financial examinations. The 12 participating states are California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. The tool requires insurers to complete four exhibits: one quantifying AI usage, one assessing governance risk, one detailing high-risk AI systems, and one documenting AI data practices. The pilot runs through September 2026, with tool updates through October 2026 and formal NAIC adoption expected at the Fall National Meeting in November 2026.
-
In effect
Final Rule: Collection of Biometric Data From Aliens Upon En
United States · Effective 2025-12-26 · Final Rule: Collection of Biometric Data From Aliens Upon Entry to and Departure From the United States
This DHS/CBP final rule authorizes facial-biometric collection from all noncitizens on entry and exit at airports, seaports and land ports, removing prior exemptions and expanding to new travel modalities.
-
In effect
EPA AI Strategic Plan
United States · Effective 2025-10-30 · EPA AI Strategy (Oct. 30, 2025)
EPA's AI Strategic Plan governs the use of AI for environmental enforcement, pollution monitoring, satellite imagery analysis, and permit review — establishing risk classifications and human-review requirements for AI in enforcement decisions.
-
Blocked / in litigation
Harper v. Sirius XM
E.D. Mich. · Effective 2025-08-04 · Harper v. Sirius XM Radio Inc., No. 2:25-cv-12403 (E.D. Mich., filed Aug. 4, 2025)
A private class action filed in August 2025 in the Eastern District of Michigan alleges that Sirius XM Radio's automated applicant-screening tools produced unlawful disparate impact against Black and minority job applicants under Title VII. Filed shortly after the EEOC's FY2024 enforcement-focus announcement targeting Sirius XM's AI hiring systems, the case is one of the first private Title VII class actions to directly challenge a corporate AI hiring algorithm.
-
In effect
ACA § 1557 (AI in patient care)
United States · Effective 2025-05-01 · 42 U.S.C. § 18116; 45 C.F.R. § 92.210
A 2024 HHS rule says hospitals, insurers, and other covered health entities may not discriminate through clinical algorithms and AI decision-support tools, and must make reasonable efforts to find and fix bias in those tools. The requirement took effect May 1, 2025, but HHS has stayed quiet on enforcement, so its practical protection is uncertain while it stays on the books.
-
In effect
Federal AI Executive Orders
United States · Effective 2025-01-23 · Exec. Order 14179 (Jan. 23, 2025); Exec. Order of Dec. 11, 2025
The current federal posture is deregulatory: EO 14179 (January 2025) revoked the prior AI safety order and directed agencies to remove AI rules seen as barriers to innovation, leading agencies like the EEOC and CFPB to pull AI guidance. A December 11, 2025 executive order directs the DOJ to challenge state AI laws and pushes for a uniform federal framework — but it does not itself preempt state laws, which remain in force absent congressional action or court rulings.
-
In effect
DHS AI Critical Infra Framework
United States · Effective 2024-11-14 · DHS Framework (Nov. 14, 2024)
DHS released a voluntary framework that lays out the responsibilities of cloud providers, AI developers, AI deployers, critical-infrastructure owners, and civil society for the safe and secure use of AI in U.S. critical infrastructure sectors — including grid, water, financial services, and healthcare.
-
Repealed / replaced
OMB M-24-18 (superseded by M-25-22)
United States · Effective 2024-10-03 · OMB M-24-18 (Oct. 3, 2024)
OMB's original federal AI acquisition memo set rules for how agencies buy AI, including performance testing, vendor competition, and IP protections for federal AI use cases. Superseded by M-25-22 in April 2025 but established the federal baseline for AI procurement still in effect through M-25-22.
-
In effect
USDA AI Strategy
United States · Effective 2024-09-30 · USDA AI Strategy (Sept. 30, 2024)
USDA's AI Strategy governs how the department deploys AI across food safety inspection, SNAP eligibility processing, agricultural research, and farm-loan adjudication — with use-case inventory disclosure required by OMB.
-
In effect
GSA AI Procurement Guide
United States · Effective 2024-09-24 · GSA AI Guide for Government (2024)
GSA's AI procurement guide gives federal contracting officers a step-by-step playbook for buying AI — including risk classification, vendor due diligence, evaluation criteria, and contract clauses that comply with OMB M-25-22.
-
In effect
HHS ASPR AI Public Health
United States · Effective 2024-08-28 · HHS ASPR AI Framework (Aug. 28, 2024)
HHS's Administration for Strategic Preparedness and Response framework governs AI use in public-health emergencies — including pandemic modeling, vaccine distribution, and resource allocation — with bias auditing and transparency required for algorithms that affect access to scarce medical countermeasures.
-
In effect
NTIA Open Weights Report
United States · Effective 2024-07-30 · NTIA Open Weights Report (July 30, 2024)
NTIA's open-weights report concluded that the federal government should monitor — but not currently restrict — the public release of advanced AI model weights. It established the federal policy baseline that open AI models offer competitive and research benefits that outweigh current risks.
-
In effect
SSA AI Disability Adjudication
United States · Effective 2024-07-30 · SSA AI Governance Framework (July 30, 2024)
Social Security Administration governance for AI used to help adjudicate disability claims — including the Insight tool and Quick Disability Determinations. Human adjudicators must review every AI-assisted determination; AI cannot deny benefits without ALJ or examiner review.
-
In effect
NIST GenAI Profile (AI 600-1)
United States · Effective 2024-07-26 · NIST AI 600-1
NIST's voluntary GenAI Profile is the leading federal playbook for managing risks unique to generative AI: hallucinations, harmful content, intellectual property leakage, data poisoning, and CBRN misuse. Federal contractors and many enterprises adopt it as the de facto AI risk-management baseline.
-
In effect
FINRA AI Notice 24-09
United States · Effective 2024-06-27 · FINRA Reg. Notice 24-09 (June 27, 2024)
FINRA reminded broker-dealers that existing rules — supervision, recordkeeping, advertising, and anti-fraud — apply fully to AI tools, including generative AI used for customer communications, surveillance, and trading. Firms misrepresenting AI capabilities or failing to supervise AI outputs face enforcement.
-
In effect
DOE AI Energy Framework
United States · Effective 2024-04-29 · DOE AI for Energy Report (Apr. 29, 2024)
DOE's AI for Energy report sets federal expectations for how utilities, grid operators, and large compute customers use AI for grid operations, demand forecasting, and energy-resource planning — including data centers that strain regional grids.
-
In effect
FSMB AI Guidance
United States · Effective 2024-04-26 · FSMB Policy (Apr. 26, 2024)
FSMB adopted a national framework guiding all U.S. state medical boards on what physicians must do when using AI: maintain transparency with patients, ensure AI tools are appropriate to use, supervise AI outputs, and protect patient privacy. States are adopting it as the model framework.
-
In effect
Treasury AI Cyber Report (Fin. Services)
United States · Effective 2024-03-27 · Treasury Report (March 2024)
Treasury released a sector-wide report outlining AI-specific cybersecurity risks facing banks and financial institutions, the gap between large and small firms in AI-fraud defense, and supervisory expectations for AI-driven fraud, deepfakes, and prompt-injection attacks.
-
In effect
NTIA AI Accountability Report
United States · Effective 2024-03-27 · NTIA AI Accountability Report (Mar. 27, 2024)
The Commerce Department's NTIA released the federal government's flagship policy report on AI accountability — concluding that independent AI audits, evaluations, and disclosure mechanisms are essential and recommending federal investment in the AI accountability ecosystem.
-
In effect
NIST AISI / AISIC
United States · Effective 2024-02-08 · NIST AISI Charter (Feb. 8, 2024)
NIST stood up the U.S. AI Safety Institute and a consortium of AI developers, civil-society groups, and academic labs to develop technical guidance, test methodologies, and safety evaluations for advanced AI models — including red-teaming and dual-use foundation model evaluation.
-
In effect
CFTC AI trading-scam advisory
United States · Effective 2024-01-25 · CFTC OCEO Customer Advisory (Jan. 25, 2024)
The Commodity Futures Trading Commission warned consumers about AI-related investment scams — fraudsters promising guaranteed returns from AI trading bots, AI-generated celebrity endorsements, and AI-themed pump-and-dump schemes in crypto and forex markets. The advisory laid the groundwork for CFTC enforcement against AI-touted commodity fraud.
-
In effect
NSF NAIRR Pilot
United States · Effective 2024-01-24 · NSF NAIRR Pilot (Jan. 24, 2024)
NSF's NAIRR pilot is a two-year initiative providing U.S. academic researchers with shared access to compute, data, and AI models — establishing federal terms for responsible AI research, including bias evaluation, model documentation, and access guardrails.
-
In effect
NAIC AI Model Bulletin (Insurance)
United States · Effective 2023-12-04 · NAIC Model Bulletin: Use of AI Systems (Dec. 4, 2023); NAIC Impl. Map (Apr. 2025)
The National Association of Insurance Commissioners adopted a Model Bulletin in December 2023 directing insurers to govern their AI responsibly — documenting AI systems, testing for bias, and overseeing third-party AI vendors. As of early 2026, over half of U.S. states and D.C. have adopted the bulletin through their own state insurance departments, making it the broadest AI governance standard in the insurance sector. It is not a federal law and has no penalties on its own, but state commissioners use it as a market-conduct examination standard.
-
In effect
CISA AI Roadmap
United States · Effective 2023-11-14 · CISA AI Roadmap (Nov. 14, 2023)
CISA's AI Roadmap outlines how the U.S. cybersecurity agency will use AI to defend networks, secure AI systems against attacks, and protect critical infrastructure from AI-enabled threats — including deepfakes and AI-driven cyberattacks on the 16 critical-infrastructure sectors.
-
In effect
EEOC SEP FY24-28 (AI priority)
United States · Effective 2023-09-21 · 88 Fed. Reg. 65042
EEOC's Strategic Enforcement Plan elevates algorithmic and AI hiring discrimination to one of the agency's top investigation priorities through FY 2028 — even after the agency removed its 2023 AI technical assistance documents in January 2025.
-
In effect
ED AI in Education Report
United States · Effective 2023-05-24 · ED OET Report (May 24, 2023)
The Education Department's first major AI report set federal policy direction for AI in K-12 and higher education — calling for human-centered design, educator oversight, equity safeguards, and a moratorium on high-stakes uses of AI to evaluate students or teachers without strong evidence and oversight.
-
In effect
FDA AI Drug/Bio Guidance
United States · Effective 2023-05-10 · FDA Discussion Paper (May 2023); CDER/CBER Draft Guidance (Jan. 2025)
FDA published a framework setting expectations for how drug and biologics companies use AI/ML across drug discovery, clinical trials, postmarket safety surveillance, and manufacturing. The framework signals that AI used in regulatory submissions must be transparent, validated, and reproducible.
-
In effect
DOJ Civil Rights AI Statement
United States · Effective 2023-04-25 · DOJ-CFPB-EEOC-FTC Joint Statement (Apr. 25, 2023)
DOJ joined three other federal agencies in an interagency statement confirming that existing civil rights laws — Fair Housing Act, ECOA, Title VII, ADA — apply fully to AI and algorithmic systems. AI does not create a 'liability shield' for discrimination.
-
In effect
NIST AI RMF (voluntary AI risk framework)
United States · Effective 2023-01-26 · NIST AI 100-1 (AI RMF 1.0); NIST AI 600-1
A voluntary federal framework that helps organizations identify, measure, and manage risks from AI systems — including bias, safety, and security issues. It creates no legal rights for individuals, but it has become the de facto standard referenced by regulators, several state AI laws, and federal contractors.
-
In effect
OSTP AI Bill of Rights Blueprint
United States · Effective 2022-10-04 · OSTP Blueprint (October 2022)
The Blueprint laid out five non-binding principles for protecting Americans from automated systems: safe and effective systems, algorithmic discrimination protections, data privacy, notice and explanation, and human alternatives. It remains the most widely cited federal articulation of AI rights and is referenced by state AI laws.
-
In effect
FTC AI Guidance (2021)
United States · Effective 2021-04-19 · FTC Business Guidance (Apr. 19, 2021)
FTC's foundational AI compliance blog warning that biased algorithms can violate FTC Act Sec. 5, FCRA, and ECOA. Sets the agency's enforcement posture on deceptive and unfair AI practices.
-
In effect
Interagency AI/ML Risk Mgmt (OCC/Fed/FDIC)
United States · Effective 2021-03-31 · 86 Fed. Reg. 16837; SR 11-7; OCC Bulletin 2011-12
Banking regulators issued a joint request for information setting their supervisory expectations for banks using AI and machine learning — covering model risk, fair lending, third-party AI vendors, and consumer-protection compliance. The 2011 model-risk-management guidance (SR 11-7) governs AI underwriting models.
-
Proposed / pending
Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757)
United States · Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757)
The U.S. House passed H.R. 7757 (267-117), imposing obligations on AI chatbot providers and online platforms to protect minors, including AI disclosure, crisis resources, use-break prompts, and policies against sexual exploitation and age-restricted content.
-
Proposed / pending
FTC Proposed Policy Statement — AI Accuracy (July 2026)
United States · FTC Proposed Policy Statement on Suppression of Accuracy in AI Systems, 91 Fed. Reg. ___ (July 7, 2026) (Docket 2026-13628)
The Federal Trade Commission published a proposed policy statement in the Federal Register on July 7, 2026 warning that AI companies that steer outputs toward undisclosed ideological objectives (rather than user-requested accuracy) may be engaging in deceptive practices under Section 5 of the FTC Act. The statement was issued pursuant to a Trump Executive Order directing the FTC to clarify how Section 5 applies to AI. Notably, the proposed statement also suggests that state laws requiring AI systems to alter outputs — including some state AI bias and accuracy mandates — may conflict with federal consumer protection law, raising preemption concerns. Public comments are due July 31, 2026. The statement is proposed, not final, and does not itself impose any legal obligations.
-
Proposed / pending
2026-10602
United States · HHS 2026-10602
The Food and Drug Administration (FDA or the Agency) is extending the comment period for the notice entitled "AI-Enabled Optimization of Early-Phase Clinical Trials Pilot Program; Request for Information" that appeared in the Federal Register of April 29, 2026. In the notice, FDA requested comments to solicit input on a proposed pilot program to assess how artificial intelligence (AI)-enabled technologies can improve efficiency, speed, and quality of decision- making in early phase clinical trials. The Agency is taking this action in response to a request for an extension to allow interested p
-
Proposed / pending
2026-11353
United States · FCC 2026-11353
In this document, the Federal Communications Commission (FCC or Commission) adopted a Notice of Proposed Rulemaking (NPRM) that kicks off a process to examine how the Commission can make some of its high-cost mechanisms even more efficient and effective into the future. Ensuring a predictable High-Cost Program for years to come--call it High-Cost Modernization--will provide continuing support for our Build America Agenda, supercharge American leadership in Artificial Intelligence (AI) by efficiently supporting the broadband-capable networks upon which AI-enhanced applications and services will
-
Enacted (not yet in effect)
2026-10347
United States · ED 2026-10347
The Department of Education (Department) announces a final priority and definitions for use in currently authorized discretionary grant programs or programs that may be authorized in the future. The Secretary may choose to use the entire priority for a grant program or a particular competition or use one or more of the priority's component parts. The final priority and definitions augment the initial set of three Secretary's Supplemental Priorities on Evidence-Based Literacy, Educational Choice, and Returning Education to the States published as final priorities on September 9, 2025 (90 FR 435
-
Proposed / pending
2026-12205
United States · GSA 2026-12205
The General Services Administration (GSA) is seeking public comment on the draft of a new General Services Administration Acquisition Regulation (GSAR) clause regarding basic safeguarding of data within Large Language Model Artificial Intelligence Systems (LLMs). Due to the complexity of the issue, GSA is publishing this notification and draft clause to gather feedback from stakeholders before taking future action (e.g., deviation and/or formal rulemaking).
-
In effect
2026-07087
United States · ED 2026-07087
The Department of Education (Department) announces one priority and related definitions for use in currently authorized discretionary grant programs or programs that may be authorized in the future. The Secretary may choose to use an entire priority for a grant program or a particular competition or use one or more of the priority's component parts. This priority and definitions augment the initial set of three Secretary's Supplemental Priorities on Evidence- Based Literacy, Educational Choice, and Returning Education to the States published as final priorities on September 9, 2025; the additi
-
Enacted (not yet in effect)
2026-07084
United States · ED 2026-07084
The Department of Education (Department) announces a final priority and definitions for use in currently authorized discretionary grant programs or programs that may be authorized in the future. The Secretary may choose to use the entire priority for a grant program or a particular competition or use one or more of the priority's component parts. This priority and definitions augment the initial set of three Secretary's Supplemental Priorities on Evidence-Based Literacy, Educational Choice, and Returning Education to the States published as final priorities on September 9, 2025; the additional
-
Blocked / in litigation
Mobley v. Workday (AI Hiring Bias)
United States · Mobley v. Workday, Inc., No. 3:23-cv-00770 (N.D. Cal.)
Derek Mobley's collective action suit in federal court alleges that Workday's AI hiring and screening tools systematically discriminated against Black, disabled, and older job applicants — denying him hundreds of opportunities. As of June 2026, the case has survived multiple dismissal motions; a court authorized notice to class members in February 2026 (March 7 opt-in deadline), and the court rejected Workday's argument that older workers can't be 'applicants' under the ADEA. The case is in discovery and could establish landmark precedent on AI vendor liability.
-
Proposed / pending
Stop Spying Bosses Act (Senate, 2026)
United States · Stop Spying Bosses Act, introduced June 18, 2026, U.S. Senate (Markey/Schatz/Booker et al.)
The Stop Spying Bosses Act, introduced June 18, 2026 in the U.S. Senate by Senators Markey, Schatz, and Booker, would sharply limit what data employers can collect on workers and how they can use it. Under the bill, employers could only collect data strictly necessary for a defined legitimate work purpose, and would be prohibited from monitoring union activity, political or religious views, immigration status, off-duty conduct, or health information. Biometric data collection — fingerprints, voiceprints, iris scans, facial maps, gait patterns — would require express consent and a legitimate work purpose. The bill would also prohibit using collected data to predict worker behavior, emotions, or beliefs unrelated to job performance. Companion legislation is the Senate No Robot Bosses Act (also introduced June 18, 2026). Senate companion to the House-side No Robot Bosses Act (HB 6371).
-
Proposed / pending
FTC CARS Rule (AI auto)
United States · 16 C.F.R. Part 463; 89 Fed. Reg. 590
The FTC rule targets deceptive auto-dealer practices, including AI-powered tools used in financing offers and add-on sales. The rule's compliance date is stayed pending Fifth Circuit litigation, but core deception standards still apply under FTC Act Section 5.
-
Proposed / pending
FTC Commercial Surveillance ANPR
United States · 87 Fed. Reg. 51273
The FTC's advance notice of proposed rulemaking on 'commercial surveillance and data security' asked whether to write rules limiting how companies collect data, train AI models on consumers, and use automated decision-making. The proceeding is technically open but has not advanced to a notice of proposed rulemaking.
-
Repealed / replaced
EO 13960 (federal AI use)
United States · Effective 2020-12-03 · Exec. Order No. 13960, 85 Fed. Reg. 78939 (Dec. 8, 2020)
President Trump's December 2020 executive order set nine principles for federal agency AI use (lawful, accurate, safe, understandable, accountable, etc.) and required each agency to publish an annual public inventory of its AI use cases. The annual AI use case inventories continued under EO 14110 (Biden) and EO 14179 (Trump-II) — making EO 13960 the foundational federal-AI-transparency baseline.
-
Blocked / in litigation
3:26-cv-05949
District Court, N.D. California · District Court, N.D. California — 3:26-cv-05949
Gagleard v. Perplexity AI, Inc. — 360 P.I.: Other
-
Expired
SEC PDA Rule (proposed)
United States · SEC Release Nos. 34-97990 / IA-6353 (proposed July 26, 2023); withdrawn via Release No. 33-11377 (June 12, 2025)
This SEC proposal (July 2023) would have required broker-dealers and investment advisers to eliminate or neutralize conflicts of interest from AI/predictive-analytics technologies used in investor interactions. It DID NOT take effect: on June 12, 2025 the SEC formally withdrew it (one of 14 Biden/Gensler-era proposals withdrawn), so no rule is in force — any future rulemaking would have to start over with a new proposal.
-
Expired
Algorithmic Accountability Act (2019, died)
United States · H.R. 2231 / S. 1108, 116th Cong. (2019) — died in committee
Sens. Wyden and Booker and Rep. Clarke introduced the first federal Algorithmic Accountability Act on April 10, 2019. It would have empowered the FTC to require large companies to assess and address bias, discrimination, and privacy risks in 'automated decision systems.' Never received a committee vote — but it set the template for every subsequent federal and state algorithmic-accountability bill.
-
Expired
Algorithmic Accountability Act (2022, died)
United States · S. 3572 / H.R. 6580, 117th Cong. (2022) — died in committee
Sens. Wyden and Booker and Rep. Clarke reintroduced an expanded Algorithmic Accountability Act on Feb. 3, 2022. It would have required impact assessments for 'augmented critical decision processes' across employment, housing, credit, education, and healthcare. Died in committee but became the most-cited federal AI bill of the 117th Congress.
-
Expired
Algorithmic Accountability Act (2023, died)
United States · S. 2892 / H.R. 5628, 118th Cong. (2023) — died in committee
The third iteration of the Algorithmic Accountability Act, reintroduced on Sept. 21, 2023 with refined definitions and FTC rulemaking authority. Like its predecessors it never received committee action — but it remains the leading federal ADS-impact-assessment template.
-
Expired
Algorithmic Justice Act (Markey/Matsui, died)
United States · S. 1896 / H.R. 3611, 117th Cong. (2021) — died in committee
Sen. Markey and Rep. Matsui's May 2021 bill would have banned discriminatory algorithmic processes on online platforms, required plain-language algorithm disclosure to users, and created a cross-agency task force on algorithmic discrimination. Died in committee but became a citation anchor for later FTC trade-rule petitions.
-
Expired
OBBBA §43201 (stripped)
United States · OBBBA §43201 — stripped July 1, 2025 (99-1); OBBBA enacted July 4, 2025
Section 43201 of the One Big Beautiful Bill Act (H.R. 1, 2025) would have imposed a 10-year moratorium on state AI laws. The Senate stripped it on a 99-1 vote on July 1, 2025 — the most significant failed federal preemption attempt against state AI regulation. The OBBBA was signed into law on July 4, 2025 without the AI moratorium.
-
Expired
FY26 NDAA AI preemption (failed)
United States · FY26 NDAA preemption amendment (S.Amdt. to S. 2296) — not adopted
A Cruz-led amendment to the FY26 NDAA would have preempted state AI regulation under a defense-nexus theory. The amendment was not adopted in conference, the second failed federal preemption attempt within a year.
-
Expired
APRA AI provisions (dead)
United States · APRA Discussion Draft (Apr. 2024) — pulled from markup June 27, 2024
The American Privacy Rights Act discussion draft (April 2024) included algorithmic impact assessment requirements. It was pulled from House markup in June 2024 — the last serious federal ADMT framework before the current 2026 federal drafts.
State automated decision-making rules (251)
-
In effect
Washington SHB 1672 (employee monitoring notice, ADS restrictions, emotion AI ban)
Washington · Effective 2026-07-01 · Wash. SHB 1672 (2025 Session), effective July 1, 2026
Washington SHB 1672, effective July 1, 2026, is one of the most comprehensive U.S. employer monitoring laws. Employers must give employees 15 calendar days' written notice before any monitoring begins or before any change to monitoring. Notice must specify what is monitored, the method used, the purpose, who can access the data, and how long it is retained. The law prohibits off-duty monitoring, monitoring in private spaces (bathrooms, locker rooms), and monitoring personal vehicles. It restricts AI-based emotion recognition, gait recognition, and facial recognition in employment-related decisions. Employers must conduct impact assessments before deploying automated decision systems and must provide human oversight of ADS-driven performance evaluations. Employees have a private right of action with damages of at least $500 per violation plus attorney fees. Civil penalties may reach $10,000 per violation. The law applies to any employer with one or more Washington employees, including remote employees of out-of-state companies.
-
In effect
Seminole Nation (OK) Data Center / GenAI Moratorium
Seminole Nation of Oklahoma · Effective 2026-03-07 · Seminole Nation of Oklahoma Tribal Council Resolution (Mar. 7, 2026)
First tribal council in the United States to fully bar inquiries, discussions, and development of any data center or generative AI hyperscale infrastructure within Seminole Nation territory. Unanimous (24-0) vote citing water-contamination and sovereignty concerns.
-
In effect
CA CPPA ADMT Regs
CA · Effective 2026-01-01 · 11 Cal. Code Regs. §§ 7200-7232
California's privacy agency finalized binding regulations governing automated decision-making and AI used to make significant decisions about Californians — including hiring, housing, education, healthcare, financial services, and ads to minors. Consumers gain rights to pre-use notice, opt-out, and access to information about how AI made the decision.
-
In effect
CCPA/CPRA + ADMT Regulations
California · Effective 2026-01-01 · Cal. Civ. Code § 1798.100 et seq.; Cal. Code Regs. tit. 11, div. 6
California's main privacy law gives consumers rights to know, delete, correct, and opt out of the sale or sharing of their personal information. New regulations finalized in 2025 add rights around automated decision-making technology (ADMT): businesses using ADMT for significant decisions (jobs, housing, credit, healthcare) must give pre-use notice, let people opt out, and provide access to how decisions were made.
-
In effect
HB 3773 (AI Employment Discrimination)
Illinois · Effective 2026-01-01 · P.A. 103-0804, amending 775 ILCS 5
Illinois employers may not use AI in ways that discriminate against protected classes in recruitment, hiring, promotion, discipline, discharge, or other employment terms, and may not use zip codes as a proxy for protected characteristics. Employers must notify workers and applicants when AI is used in employment decisions.
-
In effect
California CRC rules (FEHA anti-bias law applied to AI hiring/employment tools)
California · Effective 2025-10-01 · Cal. Code Regs. tit. 2 (Civil Rights Council ADS regulations); Cal. Gov. Code 12940 et seq. (FEHA)
These regulations make clear that California's existing anti-discrimination employment law applies to automated-decision systems, including AI tools used in hiring, promotion, and other job decisions. Employers cannot use AI or algorithmic tools that discriminate against people based on protected characteristics such as race, sex, age, or disability, and must keep records related to these systems for at least four years.
-
Enacted (not yet in effect)
Illinois SB 3114 — Transparency in Downcoding Act
Illinois · Effective 2028-01-01 · Illinois PA 104-0568 (SB 3114), signed July 10, 2026; effective January 1, 2028 (Transparency in Downcoding Act)
Illinois Senate Bill 3114, the Transparency in Downcoding Act (Public Act 104-0568), signed by Governor Pritzker on July 10, 2026, prohibits health insurers from using any automated process, system, or tool — including artificial intelligence — as the sole basis for downcoding a medical claim based on medical necessity, unless a human employee or contractor has first reviewed the covered individual's medical record. The law also imposes a parallel obligation on health care providers, prohibiting providers from using AI to submit a health benefits claim without review by a provider or other person involved in developing the claim. Insurers must provide a clear explanation when downcoding, including the rationale and the coding changes applied. Downcoding cannot be based solely on diagnosis codes or targeted at providers who treat complex patients. The Act is effective January 1, 2028.
-
Enacted (not yet in effect)
NJ Fair Pricing and Transparency Act S3952 (2026)
NJ · Effective 2027-07-23 · N.J. S3952 / A3929 (222nd Legislature, 2026) — signed July 23, 2026; effective July 23, 2027
Governor Meredith Sherrill signed New Jersey S3952/A3929, the Fair Pricing and Transparency Act, on July 23, 2026, making New Jersey the third state to ban surveillance-based grocery pricing, following Maryland and Connecticut. The law prohibits retail food stores from setting individualized prices based on a customer's personal data, purchasing history, or tracked attributes. It also imposes a one-year moratorium on electronic shelf labels (ESLs). Effective July 23, 2027. Notably, the law includes a private right of action for injured consumers — the first state surveillance-pricing law to do so.
-
Enacted (not yet in effect)
NJ Forbidding the Algorithmic Inflation of Rent (FAIR) Act
New Jersey · Effective 2027-07-20 · Forbidding the Algorithmic Inflation of Rent (FAIR) Act, N.J. P.L.2026, c.43 (A3497/S451), signed July 20, 2026
New Jersey Governor Sherrrill signed the Forbidding the Algorithmic Inflation of Rent (FAIR) Act on July 20, 2026, making New Jersey the first state to ban landlords from using algorithmic revenue-management software that coordinates rent-setting using nonpublic competitor pricing and occupancy data. The law, effective July 20, 2027, prohibits residential landlords from using or paying for such software and from receiving pricing recommendations derived from competitors' nonpublic data. RealPage and similar tools are directly targeted.
-
Enacted (not yet in effect)
NJ FAIR Act algorithmic rent ban (2026)
NJ · Effective 2027-07-01 · N.J. A3497/S451 (222nd Legislature, 2026) — Assembly vote June 30, 2026; Senate vote June 18, 2026; awaiting governor's signature
The New Jersey FAIR Act (A3497/S451) would prohibit landlords and property managers from using algorithmic rent-pricing software — programs that set or recommend rents using pooled non-public competitor data, such as RealPage — to inflate apartment rents. The Assembly cleared it June 30, 2026; the Senate cleared it June 18, 2026. Governor Sherrill pledged in March 2026 to sign it. If signed, New Jersey would join the wave of algorithmic rent ban jurisdictions (Seattle, San Diego, Minneapolis, Connecticut).
-
Enacted (not yet in effect)
Georgia SB 544 (health insurer AI)
Georgia · Effective 2027-01-01 · Ga. SB 544 (2026), signed May 5, 2026, eff. Jan. 1, 2027
Georgia's SB 544, signed May 5, 2026 and effective January 1, 2027, lets health insurers use AI in the prior-authorization process to automate tasks and assist decision-making, but bars them from issuing an adverse determination (a denial) without the review and approval of a licensed health care provider. In short: AI can help, but a licensed human has to sign off before your care is denied.
-
Enacted (not yet in effect)
Utah SB 319 (health insurer AI)
Utah · Effective 2027-01-01 · Utah SB 319 (2026), enacted March 19, 2026, eff. Jan. 1, 2027
Utah's SB 319, enacted March 19, 2026 and effective January 1, 2027, requires health insurers to disclose to the Utah Insurance Department, to providers, and to enrollees whether AI is used to review prior-authorization requests. It also requires that a health professional's adverse determination be based on their own independent medical judgment — not dictated by an AI recommendation.
-
Enacted (not yet in effect)
Washington HB 2225 (AI chatbot disclosure, minor protections, crisis protocols)
Washington · Effective 2027-01-01 · Washington HB 2225 (2026), effective January 1, 2027
Washington's AI Companion Chatbot Safety Act (HB 2225), signed March 24, 2026, requires operators of AI companion chatbots to clearly disclose to all users that they are interacting with AI, not a human. The disclosure must be repeated every three hours for adult users and every one hour for minor users. Operators must implement suicide and self-harm crisis protocols for all users, protect minors from manipulative engagement mechanics, and restrict access to adult content. The law includes a private right of action, allowing affected individuals to sue operators. It takes effect January 1, 2027.
-
Enacted (not yet in effect)
Oregon SB 1546 (AI companion chatbot disclosure + private right of action)
Oregon · Effective 2027-01-01 · Or. SB 1546 (2026 Reg. Sess.), effective January 1, 2027
Oregon's AI Companion Chatbot Safety Act (SB 1546), signed March 31, 2026 and effective January 1, 2027, is the first U.S. chatbot law to include a direct private right of action. It regulates operators of 'AI companions' — defined as AI systems designed to simulate a sustained human-like relationship and retain contextual information across interactions. Operators must: clearly and repeatedly disclose that the system is AI, not a human (recurring disclosure every three hours for adults and every hour for minors); implement protocols to detect suicidal ideation or self-harm and direct users to crisis resources; protect minors from manipulative engagement mechanics (variable-ratio reinforcement, unpredictable rewards). Any person harmed by a violation may sue directly for $1,000 per violation, any greater actual damages, injunctive relief, and attorney fees. The law was passed near-unanimously by the Oregon legislature on March 5, 2026.
-
Enacted (not yet in effect)
AI Safety Measures Act (frontier model audits)
Illinois · Effective 2027-01-01 · IL SB315 (104th General Assembly, 2025-2026)
Illinois is the first state to require independent third-party safety audits of the largest 'frontier' AI developers (companies like OpenAI, Anthropic, and Google DeepMind). Covered developers — those with >$500M annual gross revenue whose models meet defined compute thresholds — must publish and annually update a frontier AI safety framework addressing catastrophic risks (defined as incidents threatening 50+ deaths, serious injuries, or $1B+ in damages), file transparency reports before deploying new or substantially modified models, report critical safety incidents within 72 hours (24 hours for imminent harm), and protect whistleblowers. Enforced by the Illinois Emergency Management Agency and Office of Homeland Security with the Attorney General; civil penalties; no private right of action. Law takes effect January 1, 2027; audit requirements operative January 1, 2028.
-
Enacted (not yet in effect)
CO AI Act (SB 24-205)
CO · Effective 2027-01-01 · Colo. Rev. Stat. §§ 6-1-1701 to 6-1-1707; SB 24-205 (2024)
Colorado was the first state to enact a comprehensive AI law regulating high-risk AI used to make consequential decisions about Coloradans — including credit, insurance, employment, housing, healthcare, and government services. It requires risk management, bias audits, and consumer disclosure; deceptive AI practices are deemed unfair under the Colorado Consumer Protection Act.
-
Enacted (not yet in effect)
Iowa HF 2635 (no AI-only prior-auth denials)
Iowa · Effective 2027-01-01 · Iowa H.F. 2635, 91st Gen. Assemb. (2026), Sec. 514F.8(2A), eff. Jan. 1, 2027
Iowa lets a utilization review organization use an AI-based algorithm or system to conduct an initial review of a prior-authorization request, but forbids relying on AI as the sole basis to deny, delay, or downgrade a medical-necessity prior-authorization request. A qualified human reviewer — a clinical peer or qualified reviewer — must make the binding determination.
-
Enacted (not yet in effect)
MD HB 1339 (Automated Decision Systems, 2026)
Maryland · Effective 2026-10-01 · Md. HB 1339 (2026 Reg. Sess.)
Maryland employers that use automated decision systems in hiring, promotion, or termination decisions must disclose to applicants and employees that an automated system is being used. Employers must also conduct and retain impact assessments evaluating whether their ADS produces disparate outcomes by race, sex, or other protected characteristics. Penalties run up to $10,000 per violation. Takes effect October 1, 2026.
-
In effect
Maine mental-health AI limits (2026)
Maine · Effective 2026-07-29 · Maine LD 2082 / HP 1397 (P.L. 2026, Ch. 687, 132nd Leg.); signed April 13, 2026; eff. July 29, 2026
Maine enacted LD 2082 (signed April 13, 2026 by Governor Janet Mills; effective July 29, 2026) limiting how licensed mental health professionals can use AI: only for administrative and limited supplementary tasks. AI may not make therapeutic communications, treatment decisions, or independently interact with patients. Professionals must get patient consent before using ambient-listening or other AI-powered recording tools.
-
In effect
Maine LD 61 (employer surveillance disclosure & prohibition)
Maine · Effective 2026-07-14 · Maine P.L. 2025, Ch. 524 (LD 61 / H.P. 25), 26 M.R.S. § 620-A, effective July 14, 2026
Maine's LD 61 (P.L. 2025, Ch. 524) requires employers to notify employees before any surveillance begins and to disclose surveillance practices to job applicants during interviews. Employers must provide annual written notice to all current employees describing what is monitored, how, and why. Employees may refuse installation of monitoring software on their personal devices. The law prohibits audiovisual monitoring in an employee's home, personal vehicle, or personal property. Civil fines of $100–$500 apply per violation. The law covers all public and private employers in Maine. Effective July 14, 2026.
-
In effect
Indiana HB 1271 (AI claims downcoding)
Indiana · Effective 2026-07-01 · Ind. HB 1271 (2026), enacted March 4, 2026, eff. July 1, 2026
Indiana's HB 1271, enacted March 4, 2026 and effective July 1, 2026, bars health insurers from using AI tools as the sole basis to 'downcode' a claim (reduce it to a cheaper billing code) without a health professional reviewing the patient's medical record. It also bars health care providers from using AI to submit claims without a review by the provider or a billing professional. Unlike most 2026 health-AI laws, it is not limited to prior authorization.
-
In effect
AZ HB 2175 (AI Insurance Denial — Physician Review)
Arizona · Effective 2026-07-01 · Ariz. HB 2175 (57th Leg., 1st R.S. 2025), signed May 12, 2025, eff. July 1, 2026
Arizona HB 2175 requires health insurers and managed-care organizations to have a licensed physician or medical director individually review each case before denying a health insurance claim or prior-authorization request based on medical necessity or experimental status. Insurers may not rely solely on AI algorithms, automated decision-support tools, or algorithmic recommendations to deny coverage. The law directly targets automated prior-authorization systems that issue denials without physician involvement. Signed May 12, 2025, effective July 1, 2026. Arizona is among the first states to specifically prohibit AI-only health insurance denials by statute.
-
In effect
RI Therapy Chatbot Ban (2026)
Rhode Island · Effective 2026-06-22 · Rhode Island H 7349 / S 2197 (2026), signed June 22, 2026
Rhode Island Governor Dan McKee signed H 7349 / S 2197 on June 22, 2026, prohibiting any person or business from providing therapy or psychotherapy services using artificial intelligence. Only licensed mental health professionals may conduct such sessions. The law targets AI companion chatbots and virtual therapy products that may lead users to believe they are receiving licensed mental health care from a human professional.
-
In effect
RI AI Companion Self-Harm Safety (2026)
Rhode Island · Effective 2026-06-22 · Rhode Island S 2195 / H 7350 (2026), signed June 22, 2026
Rhode Island Governor Dan McKee signed S 2195 / H 7350 on June 22, 2026, requiring operators of AI companion chatbots to implement protocols for identifying and responding to suicidal ideation. Chatbot operators must provide users experiencing suicidal ideation with crisis resources and may not discourage users from seeking professional help. Civil penalties reach $15,000 per day per violation, with proceeds directed to Rhode Island suicide prevention programs.
-
In effect
PR Ley 116-2026 (AI Bot Disclosure in Gov. Services)
Puerto Rico · Effective 2026-06-18 · Ley Núm. 116-2026 (P. del S. 622, 19th Leg. Assembly); signed June 18, 2026
Puerto Rico's Ley 116-2026 (P. del S. 622) requires PR Executive Branch agencies to notify citizens when they are interacting with an AI system, chatbot, or automated system instead of a human, and guarantees citizens the right to request human intervention at any time. Senate approved June 24, 2025; House approved June 1, 2026; signed into law by Governor Jenniffer González Colón on June 18, 2026. Puerto Rico's second enacted AI-specific law in 2026.
-
In effect
TX TDI Bulletin B-0003-26 (AI in insurance)
Texas · Effective 2026-06-12 · Texas Department of Insurance, Commissioner's Bulletin B-0003-26 (June 12, 2026)
The Texas Department of Insurance issued Commissioner's Bulletin B-0003-26 on June 12, 2026, telling insurers that decisions made with artificial intelligence must comply with Texas insurance law: AI-driven decisions may not be inaccurate, arbitrary, capricious, or unfairly discriminatory. Insurers must have a human review and approve consequential AI decisions before they take effect, maintain governance, risk-management, and audit programs for their AI systems, and keep documentation they can produce to TDI on request. TDI will police compliance through examinations and complaint monitoring.
-
In effect
CA EO N-6-26 (AI Workforce)
California · Effective 2026-05-21 · California Executive Order N-6-26 (May 21, 2026)
California's first executive order focused on AI's impact on workers. Directs state agencies, labor groups, employer groups, and AI industry partners to study AI-driven workforce displacement, recommend updates to the California WARN Act, expand dislocated-worker strategies, and identify ways to share AI's economic benefits more broadly with workers. No immediate employer mandates — but creates the framework for future legislation and regulatory action.
-
Blocked / in litigation
PA v. Character.AI (Fake Psychiatrist Chatbot)
Pennsylvania · Effective 2026-05-01 · Commonwealth v. Character Technologies, Inc. (Pa. Commonwealth Ct., filed May 1, 2026)
Pennsylvania Attorney General Josh Shapiro filed suit in Commonwealth Court on May 1, 2026, alleging that Character.AI's companion chatbot 'Emilie' impersonated a licensed Pennsylvania psychiatrist and provided ongoing psychiatric advice and treatment to users without a license. The Shapiro administration seeks a preliminary injunction requiring Character.AI to clearly disclose that its chatbots are not licensed mental health professionals and cannot provide medical treatment.
-
In effect
Connecticut algorithmic rent ban — HB 8002 (eff. Jan 1, 2026)
Connecticut · Effective 2026-01-01 · CT HB 8002 (2025 Session), eff. January 1, 2026; amends CT Antitrust Act
Connecticut enacted HB 8002 in 2025, the first state law prohibiting landlords from using 'revenue management devices' to set residential rent prices. Specifically, it bars tools that use nonpublic competitor data — such as competitors' current lease rates and occupancy levels — to recommend pricing, while allowing use of publicly available market data. Penalties run up to $100,000 for individuals and $1,000,000 for corporations per violation. Enforced under the Connecticut Antitrust Act; private parties may also bring suit. Effective January 1, 2026.
-
In effect
California AB 489 (AI healthcare chatbot misrepresentation ban)
California · Effective 2026-01-01 · Cal. AB 489 (2025-2026 Reg. Sess.), effective January 1, 2026
California AB 489, signed October 11, 2025 and in effect since January 1, 2026, prohibits AI systems from using post-nominal letters (M.D., R.N., etc.), icons, phrases, or other design elements that imply a user is receiving care from a licensed health care professional unless actual licensed professional oversight exists. It also bars marketing language suggesting clinical expertise — such as 'doctor-level,' 'clinician-guided,' or 'expert-backed' — unless the product is genuinely supported by licensed professionals. The law expands California professional licensing boards' authority to investigate and enforce violations, with each misleading representation treated as a separate offense.
-
In effect
New York S7882 (felony to use algorithms to coordinate residential rents)
New York · Effective 2025-12-15 · N.Y. Gen. Bus. Law 340-b (S7882, 2025)
This law makes it a crime to help residential landlords coordinate the rents they charge instead of competing with one another, including by operating or licensing software, a data-analytics service, or an algorithmic tool that performs a rent-setting coordination function across two or more landlords. The conduct must be done knowingly or recklessly. Violations are a Class E felony, with fines up to $1 million for a corporation and up to $100,000 or up to four years in prison for an individual.
-
In effect
Maryland HB 820 (AI in insurance utilization review)
Maryland · Effective 2025-10-01 · 2025 Md. Laws ch. 747 (HB 820); Md. Code, Ins. 15-10A-06, 15-10B-05.1
When a Maryland carrier, pharmacy benefits manager, or private review agent uses artificial intelligence or an algorithm in utilization review, the tool's determinations must be based on the individual patient's clinical history, not solely on a group dataset. The AI may not replace the role of the reviewing provider, must not result in unfair discrimination, must remain open to audit, and may not deny, delay, or modify care in a way that harms enrollees. Carriers must report to the Insurance Commissioner quarterly on adverse decisions, including whether AI was used.
-
Blocked / in litigation
Raine v. OpenAI
CA · Effective 2025-08-26 · Raine v. OpenAI, Inc., No. CGC-25-628528 (Cal. Super. Ct., S.F. Cty.)
The parents of 16-year-old Adam Raine sued OpenAI and CEO Sam Altman in August 2025, alleging ChatGPT provided their son with detailed information on suicide methods and encouraged him in conversations preceding his death. The first wrongful-death suit against a general-purpose LLM developer.
-
In effect
Cherokee Nation AI Policy
Cherokee Nation (OK) · Effective 2025-08-21 · Cherokee Nation IT AI Policy (Aug. 21, 2025); companion to Cherokee Nation EO 2024-07-CTH
Cherokee Nation's first AI policy. Governs responsible and ethical AI use across tribal government, protects Cherokee language and cultural content, and requires AI vendor questionnaires before deployment in tribal systems. Signed by Principal Chief Chuck Hoskin Jr.
-
In effect
Arkansas public entity AI/ADS policy mandate (Act 848, 2025)
Arkansas · Effective 2025-08-03 · Ark. Act 848 / HB 1958 (2025 Regular Session), eff. August 3, 2025
Arkansas Act 848 (HB 1958), signed April 17, 2025 and effective August 3, 2025, requires every state agency, school district, county, municipality, and other public entity in Arkansas to adopt a written policy governing the use of artificial intelligence and automated decision-making tools. Each policy must: (1) require a human official to make or confirm any final decision affecting citizens; (2) provide staff training on AI tool limitations; (3) make the policy publicly accessible upon request; and (4) prohibit using AI to make decisions based on political affiliation or for unlawful purposes. Passed unanimously — 93-0 in the House, 35-0 in the Senate.
-
In effect
IL WOPR (AI therapy ban)
IL · Effective 2025-08-01 · P.A. 104-0054; 225 ILCS 8/
Illinois banned AI-only therapy and made it unlawful for AI products to claim or imply they can provide mental-health treatment without a licensed clinician supervising. Aimed at consumer-protection harms from companion/therapy chatbots that misrepresent clinical credentials.
-
In effect
NV SB 199 (AI mental-health misrepresentation)
NV · Effective 2025-07-01 · 2025 Nev. Stat. Ch. 283 (AB 406); amends NRS Chs. 391, 433, 629
Nevada made it a deceptive trade practice for AI chatbots and companion apps to falsely claim — or imply — that they are licensed mental-health professionals. Aimed squarely at the growing class of GenAI 'therapy' apps that mislead vulnerable users about clinical credentials.
-
In effect
CPPA Honda ADMT settlement
CA · Effective 2025-03-12 · CPPA, In re American Honda Motor Co. (Mar. 12, 2025)
California's privacy agency fined American Honda $632,500 — its first public enforcement action — for making consumers go through hoops to exercise opt-out and access rights, including against automated decision-making and data-broker sharing. The agency signaled that ADMT (automated decision-making technology) compliance is now a top enforcement priority for AI-driven consumer profiling.
-
In effect
CA SB 1120 (AI prior auth)
CA · Effective 2025-01-01 · Cal. Stats. 2024 Ch. 879; Cal. Health & Safety Code § 1367.01
California prohibits health insurers from using AI or algorithms to deny, delay, or modify medical care — only a qualified physician can make a coverage denial. The law applies to all California-regulated health plans, including commercial, Medi-Cal managed care, and Knox-Keene plans.
-
In effect
CA AB 1008 (CCPA + AI)
CA · Effective 2025-01-01 · Cal. Civ. Code § 1798.140; AB 1008 (Stats. 2024, ch. 853)
California clarified that personal information remains protected by the CCPA even when it is embedded in or generated by AI systems — including model weights and AI-generated synthetic content about a person. Closes a loophole AI developers had used to argue training data and model outputs fell outside privacy law.
-
In effect
SB 1120 (CA Physicians Make Decisions Act)
California · Effective 2025-01-01 · Cal. Health & Safety Code § 1367.01; Cal. Insurance Code § 10123.135 (SB 1120, Stats. 2024, ch. 1020)
California was the first U.S. state to directly prohibit health insurance plans from using AI to deny, delay, or modify care. Under SB 1120, when a plan uses AI or algorithms in utilization review, a licensed physician or other qualified clinician — not an AI system — must make every medical-necessity determination. AI tools can assist in data analysis, but the final coverage decision must come from a licensed human. Insurers must disclose AI use and make their algorithms available for regulatory audits. Signed September 28, 2024; effective January 1, 2025.
-
In effect
New York LOADinG Act (oversight of state-agency automated decisions)
New York · Effective 2024-12-21 · N.Y. State Technology Law (LOADinG Act); L. 2024, ch. 674 (S7543B)
State agencies in New York must publicly list the automated decision-making tools they use, run and publish impact assessments on them, and keep meaningful human review for tools that hand out public benefits or affect people's rights, safety, or welfare. Agencies also cannot use automated systems to make internal employment decisions that would lay off or displace staff.
-
In effect
An Order Establishing the Maine Artificial Intelligence Task
Maine · Effective 2024-12-20 · An Order Establishing the Maine Artificial Intelligence Task Force
Governor Janet Mills' executive order creates a 21-member Maine Artificial Intelligence Task Force to study AI's implications for the state, protect residents from harmful AI uses, and identify opportunities for public-sector AI deployment, with a final report due to the Governor and Legislature by October 31, 2025.
-
In effect
NCAI Res. NC-24-008 (Digital Sovereignty)
National Congress of American Indians · Effective 2024-11-15 · NCAI Resolution #NC-24-008 (2024)
Defines tribal digital sovereignty as tribes' sovereign authority over physical and virtual network infrastructure and data — acquisition, storage, transmission, access, use. Explicitly notes that AI tools can circumvent tribal data collection protocols.
-
In effect
NYDFS CL 7 (2024) — Insurance AI Anti-Discrimination
New York · Effective 2024-07-11 · NYDFS Insurance Circular Letter No. 7 (2024) (July 11, 2024)
New York's Department of Financial Services issued Insurance Circular Letter No. 7 on July 11, 2024, establishing the most substantive state insurance AI rule in the country. Going beyond the NAIC Model Bulletin adopted by 24+ states, NYDFS CL No. 7 requires insurers to conduct a comprehensive 'proxy assessment' before using any AI system (AIS) or external consumer data source (ECDIS) in underwriting or pricing — and prohibits any such use unless the insurer can demonstrate the system does not produce unfair or unlawful discrimination against protected classes. When an AI-influenced adverse underwriting decision is made, the insurer must provide written notice within 15 days of the decision. Governance, documentation, and DFS market-conduct examination requirements apply immediately.
-
In effect
UT AI Policy Act (SB 149)
UT · Effective 2024-05-01 · Utah Code §§ 13-2-12, 13-72-101 et seq.; SB 149 (2024)
Utah was the first state to require regulated professionals (e.g., doctors, lawyers, accountants) to clearly disclose when consumers are interacting with generative AI, and to make companies liable under existing consumer-protection law for any deception their GenAI commits. It also created the Office of AI Policy and a regulatory sandbox.
-
In effect
CA EO N-12-23 (GenAI)
CA · Effective 2023-09-06 · Cal. Exec. Order No. N-12-23 (Sept. 6, 2023)
Governor Newsom's EO N-12-23 directs California agencies to study generative AI's risks and uses and to develop a deployment framework. It produced the 2024 GenAI Procurement and Use Guidelines, governing how state agencies acquire and use GenAI tools.
-
In effect
NCAI Res. SAC-22-026 (Emerging Tech)
National Congress of American Indians · Effective 2022-11-04 · NCAI Resolution #SAC-22-026 (2022)
NCAI resolution addressing how emerging technologies including AI can circumvent tribal data collection protocols without proper consent. Reinforces tribal authority over data flowing through AI systems.
-
In effect
IL AI Video Interview Act (2019, first-in-nation)
IL · Effective 2020-01-01 · 820 ILCS 42/1 et seq. (P.A. 101-0260, 2019; P.A. 102-0407, 2021)
Signed by Governor Pritzker on August 9, 2019, the Illinois AI Video Interview Act was the first U.S. state law specifically regulating AI in hiring. It requires employer notice, applicant consent, and explanation of how AI works before using AI to analyze a video interview. 2022 amendment (P.A. 102-0407) added demographic data collection. Still in effect 2026 at 820 ILCS 42/1 et seq.
-
In effect
CARE Principles (Indigenous Data)
Global Indigenous Data Alliance · Effective 2019-09-01 · Carroll et al., Data Science Journal 19:43 (2020); GIDA (2019)
Indigenous-authored complement to the FAIR data principles. Establishes that Indigenous data must be governed under Indigenous authority, used for Collective benefit, and handled with Responsibility and Ethics. Widely referenced in U.S. tribal research codes and increasingly in federal agency guidance.
-
In effect
NBDC Genomic Sovereignty
Native BioData Consortium · Effective 2018-01-01 · Native BioData Consortium governance protocols (est. 2018)
First U.S. Indigenous-led biorepository. Keeps Indigenous biological samples and derived genomic data under Indigenous governance and consent, with privacy-preserving protocols to prevent extractive AI/genomic research without tribal authorization. Based on the Cheyenne River Sioux Reservation in South Dakota.
-
In effect
MI UIA MIDAS Reform Rules
MI · Effective 2017-12-13 · MCL § 421.62a; 2017 Mich. Pub. Acts 224-228
After Michigan's MIDAS automated fraud-detection system wrongly accused tens of thousands of unemployment claimants of fraud and seized their tax refunds, Michigan adopted statutory and regulatory reforms requiring human review before fraud determinations, restitution for wrongful determinations, and prohibition on fully automated fraud findings.
-
In effect
VA PDD Act (2017 — first)
Virginia · Effective 2017-07-01 · Va. Code §§ 46.2-100, 46.2-908.1:1
Virginia was the first U.S. state to legalize sidewalk delivery robots. PDDs may operate on sidewalks and crosswalks (10 mph cap, 50 lb cargo limit), must carry $100,000 liability insurance and a visible operator ID, and localities may further regulate them. Starship Technologies' deployment at George Mason in 2019 traces back to this law.
-
Enacted (not yet in effect)
Delaware HB 191 (AI clinician licensure ban)
Delaware · Del. HB 191 (2026), signed April 23, 2026
Delaware's HB 191, signed April 23, 2026, prohibits any non-human entity — including an AI-powered agent — from being licensed or certified to practice as a professional nurse, advanced practice registered nurse, practical nurse, physician, or physician assistant. It also bars non-human entities from using protected professional titles or abbreviations tied to those professions.
-
Enacted (not yet in effect)
Utah SB 298 (bars AI/algorithmic transaction denials by protected traits)
Utah · Effective 2027-05-05 · Utah Code 70A-9a-902, 70A-9a-903 (S.B. 298, 2026)
Utah bars issuers of 'programmable money' from blocking or failing transactions based on a person's protected traits and lawful conduct — including political opinions or speech, religious beliefs, sex, skin color, ethnicity, sexual orientation, medical history, location, purchase or browsing history, residence, business sector, or any social-credit-style score. The prohibition explicitly reaches denials carried out through automation, computer code, algorithms, or AI. A harmed person can sue for statutory and declaratory relief plus actual and punitive damages, and a court can revoke the issuer's authorization to do business in Utah.
-
Enacted (not yet in effect)
Alabama Personal Data Protection Act (privacy / profiling opt-out)
Alabama · Effective 2027-05-01 · 2026 Ala. Acts (HB 351), Alabama Personal Data Protection Act
Alabama's comprehensive consumer privacy law gives residents the right to tell businesses to stop using their personal data for profiling that drives automated decisions with major consequences. This covers decisions about things like lending and credit, housing, insurance, education, employment, healthcare, criminal justice, and access to basic necessities. Consumers can also opt out of targeted advertising and the sale of their data. The Alabama Attorney General enforces the law, and there is no individual lawsuit right.
-
Enacted (not yet in effect)
Washington HB 1170 (AI content watermarking & provenance metadata)
Washington · Effective 2027-02-01 · Washington HB 1170 (2026), effective February 1, 2027
Washington's HB 1170, signed March 24, 2026, requires covered AI providers — those with more than one million monthly active users — to embed metadata or watermarks (provenance data) in AI-generated or materially altered images, video, and audio content. The law is enforced by the Washington Attorney General under the state's Consumer Protection Act. It takes effect February 1, 2027. Strength is rated 'limited' because the one-million-user threshold exempts many smaller AI providers, and enforcement relies on the AG rather than providing a direct private right of action.
-
Enacted (not yet in effect)
CO ADMT Act (SB 26-189, 2026)
Colorado · Effective 2027-01-01 · Colo. SB 26-189 (2026), signed May 14, 2026, eff. January 1, 2027
Colorado Governor Jared Polis signed SB 26-189 on May 14, 2026, repealing and replacing the original Colorado AI Act (SB 24-205) before it could take effect. The replacement law creates a disclosure-focused framework for 'Automated Decision-Making Technology' (ADMT) — a narrower category than the prior law's 'high-risk AI' — applicable to consequential decisions in employment, housing, healthcare, credit, education, insurance, and government services. The original Colorado AI Act had been blocked by a federal court on constitutional grounds days before the replacement was passed. The new ADMT Act takes effect January 1, 2027.
-
Enacted (not yet in effect)
Oklahoma SB 546 (opt out of profiling for significant decisions)
Oklahoma · Effective 2027-01-01 · Oklahoma Consumer Data Privacy Act, SB 546 (2026), eff. Jan. 1, 2027
Oklahoma's comprehensive consumer privacy law gives residents the right to tell a business to stop using their personal data for profiling that drives decisions carrying legal or similarly significant effects, such as those affecting credit, employment, or housing. Businesses must also run and document data protection assessments before high-risk processing, including risky profiling. The law is enforced only by the Attorney General; there is no consumer lawsuit right.
-
Enacted (not yet in effect)
SB 26-189 (Colorado ADMT Law)
Colorado · Effective 2027-01-01 · SB 26-189 (Colo. 2026)
Colorado's replacement AI law focuses on transparency rather than broad anti-discrimination duties. Starting January 1, 2027, companies using automated decision-making technology to materially influence consequential decisions (employment, housing, lending, insurance, healthcare) must notify consumers before use and provide post-decision disclosures; developers must give deployers technical documentation.
-
Enacted (not yet in effect)
SB 444 (GA AI Insurance Review)
Georgia · Effective 2027-01-01 · Ga. SB 444 (2026), sponsored by Sen. Kay Kirkpatrick
Health insurers in Georgia can't let AI alone decide your coverage. Decisions about insurance coverage for healthcare services cannot be based solely on AI systems or software tools — a qualified human reviewer must be part of every coverage determination, especially before denying treatment. Effective January 1, 2027.
-
Enacted (not yet in effect)
Maryland Predatory Pricing Act (surveillance pricing)
Maryland · Effective 2026-10-01 · 2026 Md. Laws ch. 154 (HB 895)
This law bars food retailers and third-party delivery service providers from using a consumer's personal data or dynamic (surveillance) pricing to set a higher price for tax-exempt food for a specific consumer. It also prohibits using protected-class data to offer, advertise, or sell goods in a way that withholds an accommodation or advantage from the consumer the data pertains to. Violations are treated as unfair, abusive, or deceptive trade practices under the Maryland Consumer Protection Act.
-
Enacted (not yet in effect)
CT SB 5 (2026 AI Act)
Connecticut · Effective 2026-10-01 · Conn. Public Act 26-15 (SB 5, 2026)
After years of failed attempts, Connecticut enacted a comprehensive AI law in 2026. It requires employers to disclose AI used in employment decisions, mandates disclosure when layoffs relate to AI, imposes some of the nation's strictest AI companion-chatbot rules (especially for children), and codifies that automated decision-making is no defense to discrimination claims. Most provisions start October 1, 2026.
-
In effect
Muscogee (Creek) Nation digital infrastructure task force
Muscogee (Creek) Nation · Effective 2026-07-25 · Muscogee (Creek) Nation National Council — Tribal Digital Infrastructure and Data Sovereignty Task Force (enacted 12-3, July 25, 2026)
The Muscogee (Creek) Nation National Council voted 12-3 on July 25, 2026 to establish the Tribal Digital Infrastructure and Data Sovereignty Task Force. The task force is charged with studying the potential environmental impact, effects on cultural resources and cybersecurity, and data sovereignty implications of AI systems and data center development on reservation lands. Principal Chief David Hill supported the legislation, citing community feedback about data center and AI infrastructure concerns. The task force — which includes the Principal Chief, National Council representatives, the attorney general's office, and the tribal utility authority — has 60 days to report its findings to the National Council (deadline approximately September 23, 2026). This is a study body, not a moratorium; no ban on data centers has been enacted.
-
In effect
Virginia IVO AI Safety Study (SB 384/HB 797, 2026)
Virginia · Effective 2026-07-01 · 2026 Va. Acts, SB 384 / HB 797 (JCOTS IVO Study Directive), eff. July 1, 2026
Virginia enacted SB 384 and companion HB 797 on April 13, 2026, directing the Joint Commission on Technology and Science (JCOTS) to study the feasibility of a framework for Independent Verification Organizations (IVOs) — independent bodies that would assess whether AI models and applications meet safety standards designed to prevent personal injury and property damage. This is a study directive only; it does not create any compliance obligations for AI developers or deployers today. If JCOTS recommends a framework, future legislation could require IVO certification before deployment of high-risk AI systems in Virginia.
-
In effect
NC AI Strategic Roadmap (released Jul. 1, 2026)
North Carolina · Effective 2026-07-01 · North Carolina AI Strategic Roadmap (AI Leadership Council under Executive Order 24), released July 1, 2026
North Carolina released its AI Strategic Roadmap on July 1, 2026. Developed by the AI Leadership Council that Governor Josh Stein created under Executive Order 24, the roadmap lays out 17 goals organized around three priorities: protecting North Carolinians from AI harms, preparing the workforce for AI, and using AI to improve government service delivery. As a published strategy document, it guides state agency AI adoption and safeguards but does not itself impose binding legal requirements.
-
In effect
Indiana HB 1271 (no AI-only claim downcoding)
Indiana · Effective 2026-07-01 · Ind. House Enrolled Act 1271 (2026 Reg. Sess.), eff. July 1, 2026
Indiana bars health insurers from relying on an automated process or artificial intelligence as the only reason for downcoding a claim on medical-necessity grounds; a qualified health professional must review the patient's medical record before such a downcode is applied. Health care providers likewise may not use AI to submit a claim without a human reviewing the record. Insurers must also tell providers when AI played a role in an adverse prior-authorization decision or a downcode, and providers keep appeal rights.
-
Proposed / pending
Colorado Attorney General Rulemaking for the Automated Decis
Colorado · Effective 2026-06-30 · Colorado Attorney General Rulemaking for the Automated Decision-Making Technology (ADMT) Act and Chatbot Safety Act
The Colorado Attorney General's Office opened pre-rulemaking to write rules implementing the state's Automated Decision-Making Technology Act (algorithmic-discrimination protections for high-risk AI) and the Chatbot Safety Act, taking public comment through July 13, 2026 ahead of the laws' January 1, 2027 effective date.
-
In effect
Washington SB 5395 (limits AI in health-insurance prior-auth denials)
Washington · Effective 2026-06-11 · Engrossed Second Substitute S.B. 5395, 2025-26 Reg. Sess. (Wash.)
Washington bars health carriers from using AI to deny, delay, or modify health care services on its own; a denial based on medical necessity must be made by a licensed health professional. Where AI is used in prior authorization, it must be applied fairly, comply with anti-discrimination law, and base determinations on the individual enrollee's medical history, clinical circumstances, and relevant demographic data rather than broad group data. AI tools must be reviewed for accuracy, AI policies are subject to audit by the Insurance Commissioner, and carriers must report the share of denials aided by AI.
-
In effect
Maryland HB 1563 (AI-denial reporting)
Maryland · Effective 2026-06-01 · 2026 Md. Laws ch. 165 (HB 1563); Md. Code, Ins. 15-10A-06
Among other emergency-room and post-acute care provisions, this law expands the quarterly report that carriers must submit to the Maryland Insurance Commissioner. The report must include the number of adverse decisions and whether an artificial intelligence, algorithm, or other software tool was used in making them. The Commissioner may use this information as a basis for examining the carrier.
-
In effect
SUNY Systemwide Artificial Intelligence Policy
State University of New York (SUNY) · Effective 2026-04-30 · SUNY Systemwide Artificial Intelligence Policy
SUNY's Board of Trustees approved a systemwide AI policy requiring all 64 campuses to adopt AI governance, bias evaluation, data-privacy safeguards, and heightened oversight of high-risk systems affecting students by December 31, 2026.
-
In effect
CO AG Weiser
CO · Effective 2026-04-27 · CO AG Weiser — Suspension of Colorado AI Act Rulemaking and Enforcement (x.AI v. Weiser) (2026-04-27)
AG entered joint motion to stay enforcement of SB 24-205 in xAI Corp. v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo.; Chief Judge Daniel D. Domenico; Magistrate Judge Cyrus Y. Chung). DOJ intervened on xAI's side April 24, 2026; federal court entered enforcement stay April 27, 2026. Colorado enacted SB 26-189 (signed May 14, 2026) to repeal and replace SB 24-205; enforcement suspended until rulemaking under new ADMT law by December 31, 2026.
-
In effect
Executive Order N-5-26 - Trusted AI Procurement
California · Effective 2026-03-30 · Executive Order N-5-26 - Trusted AI Procurement
This newer California executive order directs DGS and CDT to develop trust-and-safety certifications for state AI contracting (covering CSAM/NCII, harmful bias, and civil-rights violations), reforms to bar contracting with entities that unlawfully undermine privacy or civil liberties, and CDT guidance on watermarking AI-generated media.
-
In effect
AI Systems Code of Ethics and Minimum Risk Management and Go
Texas · Effective 2026-03-01 · AI Systems Code of Ethics and Minimum Risk Management and Governance Standards (1 TAC Chapter 219)
Under Government Code 2054.702 and SB 1964, the Texas Department of Information Resources adopted a statewide AI code of ethics built on seven principles (human oversight, fairness, accuracy, redress, transparency, privacy, security) plus minimum risk-management standards for heightened-scrutiny AI systems.
-
In effect
Artificial Intelligence Framework for Utah P-12 Education: G
Utah State Board of Education (USBE) · Effective 2026-03-01 · Artificial Intelligence Framework for Utah P-12 Education: Guidance on the Use of AI in Our Schools
Utah's state board of education issued an AI framework guiding students, staff, and communities on responsible and prohibited use of generative AI, with special considerations for safety, security, and privacy.
-
In effect
Attorney General Tong Memorandum on Artificial Intelligence
Connecticut · Effective 2026-02-25 · Attorney General Tong Memorandum on Artificial Intelligence
Connecticut AG William Tong issued a memorandum explaining how existing Connecticut civil rights, data privacy and security, consumer protection (unfair trade practices), and antitrust laws already apply to AI systems, signaling enforcement priorities.
-
In effect
New York S8831 (shields public employees from AI displacement)
New York · Effective 2026-02-13 · N.Y. S8831 (2025)
This law amends New York's education, state technology, and civil service laws to protect public employees from harms caused by artificial intelligence systems. It guards against AI being used in ways that would impair workers' collective-bargaining rights, lead to their discharge or displacement, transfer their job duties to an AI system, or cut their hours, wages, or benefits.
-
In effect
Executive Order 26-02 (Strategic Framework for Integration o
Missouri · Effective 2026-01-13 · Executive Order 26-02 (Strategic Framework for Integration of Artificial Intelligence within State Government Operations)
Governor Mike Kehoe ordered the Office of Administration to develop a strategic framework for integrating AI into Missouri state government, prioritizing data privacy and security, human decision-making, transparency, accountability, and data quality.
-
In effect
AI Model Policy for Ohio Districts and Schools
Ohio Department of Education and Workforce · Effective 2026-01-06 · AI Model Policy for Ohio Districts and Schools
Ohio's education department released a state model AI policy that all public, community, and STEM schools must adopt (or customize) a formal AI policy from by July 1, 2026, covering student/staff use, privacy, ethics, and vendor evaluation.
-
In effect
Kentucky Consumer Data Protection Act
Kentucky · Effective 2026-01-01 · 2024 Ky. Acts (HB 15); KRS ch. 367
Kentucky's privacy law took effect January 1, 2026, giving residents rights to access, correct, delete, and copy their personal data, and to opt out of data sales and targeted advertising. Businesses need opt-in consent for sensitive data including biometrics.
-
In effect
RI Privacy Law (RIDTPPA)
Rhode Island · Effective 2026-01-01 · R.I. Gen. Laws § 6-48.1 (2024)
Rhode Island residents can access, correct, delete, and port their data, and opt out of targeted advertising, data sales, and profiling. The Attorney General enforces with fines up to $10,000 per violation and — unusually — no cure period.
-
In effect
Indiana Consumer Data Protection Act
Indiana · Effective 2026-01-01 · 2023 Ind. Acts P.L. 94-2023 (SB 5); I.C. 24-15-1 et seq.
Indiana's privacy law, effective January 1, 2026, gives residents rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, data sales, and profiling. Enforced exclusively by the Attorney General with a permanent 30-day cure period.
-
In effect
California AB 325 (bans anticompetitive use of shared pricing algorithms)
California · Effective 2026-01-01 · AB 325 (2025), amending the Cartwright Act (Cal. Bus. & Prof. Code 16700 et seq.)
This law amends California's main antitrust statute, the Cartwright Act, to address algorithmic price-fixing. It makes it unlawful to use or distribute a common pricing algorithm — a methodology that uses competitor data to recommend, align, stabilize, set, or influence a price or term — as part of an agreement or conspiracy to restrain trade, or to coerce another party into adopting a recommended price. It also makes it easier to bring antitrust conspiracy claims.
-
In effect
TRAIGA
Texas · Effective 2026-01-01 · Tex. Bus. & Com. Code Ch. 552; Tex. HB 149 (89th Leg., R.S., 2025), TRAIGA
Texas's AI law bans specific harmful uses of AI — intentional discrimination, behavioral manipulation encouraging self-harm or crime, social scoring by government, and certain biometric identification without consent — and requires government agencies to disclose AI interactions to consumers. It includes a regulatory sandbox and preempts local AI ordinances.
-
In effect
Guidance for the Safe and Effective Use of Artificial Intell
California Department of Education · Effective 2026-01-01 · Guidance for the Safe and Effective Use of Artificial Intelligence in California Public Schools
California's education department issued voluntary guidance for K-12 districts covering human-centered AI, AI literacy, equitable access, academic integrity, data privacy (FERPA/COPPA/CCPA/SOPIPA), and procurement.
-
In effect
Guam P.L. 38-77 (AI Task Force)
Guam · Effective 2025-12-16 · P.L. 38-77 (Bill 64-38 (COR)), 38th Guam Leg. (Dec. 16, 2025)
Guam's first AI law. Creates the Guam AI Regulatory Task Force charged with developing an ethical and accountable framework for AI across government, education, public safety, and the economy. Signed by Acting Governor Joshua Tenorio December 16, 2025.
-
In effect
NJ N.J.A.C. 13:16 (bias law covers AI hiring tools)
New Jersey · Effective 2025-12-15 · N.J.A.C. 13:16 (R.2025 d.150); N.J.S.A. 10:5-1 et seq.
New Jersey's Division on Civil Rights adopted rules confirming that the state's Law Against Discrimination reaches automated employment decision tools, including AI, that automate, aid, or replace human employment decision-making. The rules define such tools broadly and give concrete examples of how they can produce a disparate impact on applicants and employees in protected classes. Employers remain responsible even for vendor-supplied tools.
-
In effect
HI DOI AI Bulletin
HI · Effective 2025-12-10 · Hawaii Insurance Commissioner Memorandum 2025-13A (2025-12-10)
The HI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in HI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
AG Sunday Leads Coalition of 42 Attorneys General in Letter
Pennsylvania · Effective 2025-12-10 · AG Sunday Leads Coalition of 42 Attorneys General in Letter to A.I. Software Companies Demanding Safeguards to Protect Vulnerable Residents from Harmful Interactions with Bots
Pennsylvania AG Dave Sunday led a coalition of 42 state attorneys general demanding that major AI chatbot companies implement testing, recall procedures, and consumer warnings to protect vulnerable users, especially children, from harmful bot interactions.
-
In effect
2025 State of Connecticut Artificial Intelligence Inventory
Connecticut · Effective 2025-12-08 · 2025 State of Connecticut Artificial Intelligence Inventory
The Department of Administrative Services Bureau of Information Technology Solutions publishes the state's annual, statutorily mandated inventory of AI systems used by state agencies, cataloging each system's vendor, capabilities, whether it informs decisions, and whether an impact assessment was done.
-
In effect
Acceptable Use Policy for Artificial Intelligence
Mississippi · Effective 2025-11-25 · Acceptable Use Policy for Artificial Intelligence
Mississippi ITS adopted an AI acceptable-use policy (implementing EO 1584) setting ten guiding principles including human oversight of AI decisions, bias testing, data-protection restrictions, and a prohibition on deepfakes and using AI for final sensitive decisions.
-
In effect
Artificial Intelligence Guideline
North Dakota · Effective 2025-11-17 · Artificial Intelligence Guideline
North Dakota Information Technology's guideline outlines best practices for secure, private, and ethical use of AI, supplementing the state's AI Policy and requiring GRC risk assessment before AI business use.
-
In effect
New York Algorithmic Pricing Disclosure Act (personalized prices need a label)
New York · Effective 2025-11-10 · N.Y. Gen. Bus. Law 349-A (art. 22-A)
If a business sets the price of a product or service using an algorithm that draws on your personal data, and then shows that personalized price to you as a New York consumer, it has to tell you so with the notice: 'THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA.' The goal is to make personalized 'surveillance pricing' visible rather than hidden. The Attorney General enforces the rule and can seek up to $1,000 per violation after a cease-and-desist notice.
-
In effect
Commonwealth Office of Technology Enterprise Policy CIO-126:
Kentucky · Effective 2025-10-06 · Commonwealth Office of Technology Enterprise Policy CIO-126: Artificial Intelligence Policy
Kentucky's Commonwealth Office of Technology enterprise AI policy bans state agency use of high-risk AI systems, mandates human review before any consequential decision, and requires transparency disclaimers, bias controls, privacy protections, training, and vendor AI-use disclosure.
-
In effect
Montana MCDPA
Montana · Effective 2025-10-01 · Mont. Code Ann. §§ 30-14-2901 et seq. (SB 384, 2023; as amended by SB 297, 2025, eff. Oct. 1, 2025)
Montana's comprehensive consumer privacy law, strengthened by 2025 amendments, gives residents rights to access, correct, delete, and opt out of data processing. The SB 297 amendment removed the 'solely automated' qualifier for profiling opt-out, meaning consumers can now opt out of any automated decision-making that involves profiling with significant effects — not just fully automated decisions.
-
In effect
Maryland Online Data Privacy Act
Maryland · Effective 2025-10-01 · 2024 Md. Laws ch. 440 (SB 541); Md. Code Ann., Com. Law §§ 14-4601–14-4626
Maryland's privacy law is stricter than most: it prohibits processing sensitive personal data unless strictly necessary for the requested service. Consumers can access, correct, delete, and port their data, and opt out of automated profiling and targeted advertising. AG enforcement began April 2026.
-
In effect
Montana HB 178 (limits on government AI use)
Montana · Effective 2025-10-01 · Mont. HB 178 (2025) (Ch. 427); codified in Title 2, MCA
Montana restricts how state and local government use AI. A government entity or state officer may not use an AI system to manipulate a person or group, to classify people in ways that cause unlawful discrimination or disparate impact, for a malicious purpose, or to surveil public spaces (with narrow exceptions). Government must disclose AI-produced material that no qualified human reviewed and disclose public-facing AI interfaces. Any AI recommendation or decision that could affect a person's rights, duties, or privileges must be reviewed by a qualified human who can reject or change it.
-
In effect
Artificial Intelligence Acceptable Use Policy
Louisiana · Effective 2025-09-29 · Artificial Intelligence Acceptable Use Policy
Louisiana's Office of Technology Services policy governs employee AI use, prohibiting entry of confidential/restricted state data into commercial AI, barring AI from making independent consequential decisions, and requiring human verification, AI-content labeling, and use of only state-approved systems.
-
In effect
Executive Order No. 24: Advancing Trustworthy Artificial Int
North Carolina · Effective 2025-09-02 · Executive Order No. 24: Advancing Trustworthy Artificial Intelligence That Benefits All North Carolinians
Governor Josh Stein's order establishes an AI Leadership Council and an AI Accelerator within NCDIT and requires each Cabinet agency to form an AI Oversight Team and submit AI use cases for risk assessment.
-
In effect
TX Government AI Governance (Subchapter S / SB 1964)
Texas · Effective 2025-09-01 · Tex. S.B. 1964, 89th Leg., R.S. (2025); Tex. Gov't Code ch. 2054, subch. S
Texas now requires state agencies to catalog the artificial intelligence systems they use and to give extra review to higher-risk systems that influence consequential decisions about people. The state's Department of Information Resources must publish a statewide AI code of ethics and set baseline rules for managing AI risk and governance, and agencies must run assessments on their highest-scrutiny systems. When a member of the public interacts with a government AI system, the agency has to tell them they are dealing with AI. If an agency or its vendor breaks these rules, the attorney general can go to court to stop the violation and can void a vendor's contract that caused it.
-
In effect
TX SB 815 (No AI-Only Insurance Denials)
Texas · Effective 2025-09-01 · Tex. S.B. 815, 89th Leg., R.S. (2025); Tex. Ins. Code Sec. 4201.156
Texas bars a utilization review agent from using an automated decision system — including certain artificial intelligence — to make an adverse determination, in whole or in part, about whether health care is medically necessary or appropriate. Such coverage denials must involve human clinical judgment, though the law still allows algorithms and AI for administrative support and fraud detection. The Texas Department of Insurance may audit and inspect how utilization review agents use these systems. Violations are subject to the sanctions, cease-and-desist orders, and administrative penalties already available under the Insurance Code.
-
In effect
Adoption and Usage of Artificial Intelligence: Guidelines an
Michigan · Effective 2025-08-09 · Adoption and Usage of Artificial Intelligence: Guidelines and Responsibilities
Michigan's Department of Technology, Management and Budget issued guidelines establishing responsibilities for ethical AI use across state agencies, requiring data-classification awareness and human-in-the-loop review of AI-generated content.
-
In effect
Artificial Intelligence (AI) Governance Policy, Standard, an
Idaho · Effective 2025-08-01 · Artificial Intelligence (AI) Governance Policy, Standard, and Guideline
Idaho ITS's enterprise AI governance policy establishes a risk-classification framework, oversight responsibilities, and implementation requirements for AI use across state agencies and departments.
-
In effect
Minnesota Consumer Data Privacy Act
Minnesota · Effective 2025-07-31 · 2024 Minn. Laws ch. 123 (HF 4757); Minn. Stat. §§ 325M.01–.21
Minnesota's privacy law gives residents data rights plus something unique: the right to question automated profiling decisions with significant effects — including the right to know why the decision was made and what would change the outcome. Full AG enforcement began February 2026.
-
In effect
Executive Order 51 (2025): First-In-The-Nation Agentic Artif
Virginia · Effective 2025-07-11 · Executive Order 51 (2025): First-In-The-Nation Agentic Artificial Intelligence (AI) Empowered Statewide Regulatory Review
Governor Youngkin's order launches a pilot using agentic AI to scan the Commonwealth's regulations and guidance documents for redundant or outdated requirements and directs executive-branch agencies to incorporate AI into their periodic regulatory reviews.
-
In effect
MA AG
MA · Effective 2025-07-10 · MA AG — $2.5M Earnest Operations Settlement (AI Underwriting Discrimination) (2025-07-10)
Settlement with student-loan lender Earnest over allegations its AI underwriting model and 'Knockout Rule' produced disparate impacts on Black, Hispanic, and non-citizen applicants. Mandates AI governance, annual fair-lending testing, AG reporting.
-
In effect
Minnesota State systemwide Generative AI guidance and approv
Minnesota State (Minnesota State Colleges and Universities) · Effective 2025-07-03 · Minnesota State systemwide Generative AI guidance and approved-tools policy
Minnesota State issues systemwide generative-AI guidance authorizing secured tools like Microsoft Copilot, blocking services such as Otter.AI and Fireflies.AI for security, and ensuring system data is not used to train external AI models.
-
In effect
Minnesota SF 4097 (social-media algorithm disclosure)
Minnesota · Effective 2025-07-01 · Minn. Stat. 325M.30-325M.34; Laws 2024, ch. 114, art. 3, sec. 63 (SF 4097)
Minnesota requires large social media platforms to publicly explain how their algorithmic ranking systems decide what users see. Among other things, a platform must disclose how its own content-quality judgments and a user's stated content preferences are weighted against other ranking signals. The rules apply to platforms doing business in or targeting Minnesotans that have more than 10,000 monthly active users.
-
In effect
Tennessee Information Protection Act (opt out of automated profiling decisions)
Tennessee · Effective 2025-07-01 · Tenn. Code Ann. 47-18-3301 et seq. (TIPA); profiling opt-out at 47-18-3304
Tennessee's consumer privacy law gives state residents rights over how businesses handle their personal information, including the right to opt out of profiling that is carried out solely through automated processing and used to make decisions with legal or similarly significant effects. Businesses that act as controllers must also conduct and document data protection assessments for higher-risk processing activities, including certain profiling. The Tennessee Attorney General has exclusive enforcement authority, and there is no private right of action.
-
In effect
Va. Code 19.2-11.14 (humans, not AI, must decide bail/sentencing/parole)
Virginia · Effective 2025-07-01 · Va. Code 19.2-11.14; HB 1642 (2025), Va. Acts c. 637
Virginia requires that key criminal-justice decisions be made by a human being, even when an AI tool produces a recommendation or prediction. The rule covers pretrial detention or release, prosecution, adjudication, sentencing, probation, parole, correctional supervision, and rehabilitation. No such decision may be made without a human decision-maker, and any AI-generated recommendation is subject to any challenge or objection allowed by law.
-
In effect
New York A433 (state agencies must list AI employment tools)
New York · Effective 2025-07-01 · N.Y. State Technology Law / Civil Service Law; L. 2025, ch. 96 (A433)
Any New York State agency that uses an automated tool to help make employment decisions must publicly list those tools, and the state's IT office must keep a public inventory of state-agency AI systems that affect the public. The law also protects state workers' existing collective-bargaining rights and bars using AI to displace them.
-
In effect
The State of Maryland's Responsible AI Policy Implementation
Maryland · Effective 2025-05-01 · The State of Maryland's Responsible AI Policy Implementation Guidance (Version 1.0)
Maryland's Department of Information Technology guidance operationalizes the state's Responsible AI Policy, requiring agencies to designate an AI Lead, submit AI use cases through a risk-based intake process, complete Algorithmic Impact Assessments for high-risk systems, and document AI systems in a public inventory.
-
In effect
New Mexico AI Guidance for K-12 Education 1.0
New Mexico Public Education Department · Effective 2025-05-01 · New Mexico AI Guidance for K-12 Education 1.0
New Mexico's education department published a K-12 AI handbook covering AI literacy, guiding principles for ethical use, and a framework for responsible AI integration in classrooms.
-
In effect
Board of Regents Policy 6.28, Use of Artificial Intelligence
University System of Georgia (USG) · Effective 2025-04-16 · Board of Regents Policy 6.28, Use of Artificial Intelligence (AI) in Academic Contexts
The USG Board of Regents adopted a policy requiring all 26 institutions to establish ethical, responsible, and secure AI-use policies integrated into their academic-integrity codes.
-
In effect
Policy on the Acceptable and Responsible Use of Artificial I
Illinois · Effective 2025-04-01 · Policy on the Acceptable and Responsible Use of Artificial Intelligence
The Illinois DoIT policy governs how state agencies under the Governor's jurisdiction may develop, deploy, and use AI systems, requiring each utilizing agency to designate an AI point of contact and inventory deployed AI systems within 30 days.
-
In effect
Generative Artificial Intelligence (AI) Policy (ENTERPRISE P
Iowa · Effective 2025-03-31 · Generative Artificial Intelligence (AI) Policy (ENTERPRISE PY-AI)
Iowa's enterprise generative-AI policy, issued under Iowa Administrative Code 129-8.4(8B), sets minimum requirements and prohibited uses for generative AI, mandating human review of AI outputs and disclosure of AI-generated code.
-
In effect
Kentucky SB 4 (AI Governance)
Kentucky · Effective 2025-03-24 · 2025 Ky. Acts (SB 4)
Kentucky SB 4 establishes an AI governance framework for state government — agencies need approval before deploying AI, must conduct risk assessments, disclose AI use in decisions, and keep human oversight for consequential decisions. It also bans undisclosed AI-generated content falsely depicting people in political communications, with a civil remedy for those depicted.
-
In effect
WI DOI AI Bulletin
WI · Effective 2025-03-18 · Wisconsin OCI AI Bulletin (2025-03-18) (2025-03-18)
The WI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in WI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
WVDE Artificial Intelligence Guidance (v1.2)
West Virginia Department of Education · Effective 2025-03-01 · WVDE Artificial Intelligence Guidance (v1.2)
West Virginia's education department published AI guidance supporting superintendents, district staff, and educators in safely integrating generative AI into instruction, administration, and district operations aligned with state board policies.
-
In effect
UT System Policy IT0002 / procedure, Acceptable Use of Gener
University of Tennessee System · Effective 2025-03-01 · UT System Policy IT0002 / procedure, Acceptable Use of Generative AI
The University of Tennessee System's acceptable-use policy for generative AI bars entering FERPA/HIPAA-protected and confidential data into AI tools and requires independent verification and disclosure of AI-generated content.
-
In effect
LA Metro AI Weapons-Detection Pilot Expansion (Evolv/pillar
Los Angeles County Metropolitan Transportation Authority (LA Metro) · Effective 2025-02-27 · LA Metro AI Weapons-Detection Pilot Expansion (Evolv/pillar scanners plus AI-CCTV mobile detection)
LA Metro's board voted 10-0 to expand a one-year weapons-detection pilot using AI-powered pillar scanners and AI-CCTV mobile detection to identify concealed weapons on riders at busy stations and on buses.
-
In effect
NJ DOI AI Bulletin
NJ · Effective 2025-02-11 · New Jersey DOBI Insurance Bulletin 25-03 (2025-02-11)
The NJ Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NJ must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Responsible AI Usage Policy (107-004-190)
Oregon · Effective 2025-02-11 · Responsible AI Usage Policy (107-004-190)
Oregon Enterprise Information Services establishes enterprise-wide governance for generative and agentic AI across executive-branch agencies, requiring AI adoption plans, human review of outputs, approval of new AI uses, and use of only approved tools.
-
In effect
DE DOI AI Bulletin
DE · Effective 2025-02-05 · Delaware Domestic and Foreign Insurers Bulletin No. 148 (2025-02-05)
The DE Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in DE must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
CSU AI-Empowered University System initiative and systemwide
California State University (CSU System) · Effective 2025-02-04 · CSU AI-Empowered University System initiative and systemwide ChatGPT Edu deployment
CSU announced a first-in-the-nation systemwide AI initiative giving all 23 campuses' 460,000+ students and 63,000+ faculty/staff access to ChatGPT Edu plus AI Commons training and academic-use resources.
-
In effect
Alabama Generative AI Acceptable Use Policy (AI-GV-P2)
Alabama · Effective 2025-01-31 · Alabama Generative AI Acceptable Use Policy (AI-GV-P2)
Alabama's Office of Information Technology issued a NIST AI RMF-based acceptable-use policy requiring human review of GenAI output, annotation of AI-generated code/output, prohibition of confidential-data inputs, and OIT authorization before contractors use GenAI in state systems.
-
In effect
New Jersey Data Protection Act
New Jersey · Effective 2025-01-15 · P.L.2024, c.9 (N.J. SB 332)
New Jersey's comprehensive privacy law grants residents rights to access, correct, delete, and port personal data and to opt out of data sales and targeted advertising. Controllers must get opt-in consent for sensitive data (health, biometric, precise location) and honor universal opt-out signals since July 2025.
-
In effect
Texas v. Allstate / Arity
TX · Effective 2025-01-13 · Texas v. Allstate / Arity — Driving Data Collection Suit (TDPSA + Data Broker Law) (2025-01-13)
First-ever TDPSA and Data Broker Law suit. Alleges SDK-based collection of geolocation and driving-behavior data from 45M+ Americans via Life360, GasBuddy, etc., used to score drivers and set premiums. Active in 2026.
-
In effect
CA AG Bonta AI legal advisory
CA · Effective 2025-01-13 · CA DOJ Legal Advisory (Jan. 13, 2025)
California's Attorney General issued a legal advisory making clear that existing California consumer-protection, civil-rights, and privacy laws fully apply to AI — including the False Advertising Law, Unfair Competition Law, CCPA, and FEHA. The advisory targets AI-washing, AI-driven discrimination, hallucination-driven misrepresentations, and AI scam impersonation.
-
In effect
Attorney General Bonta Legal Advisories on the Application o
California · Effective 2025-01-13 · Attorney General Bonta Legal Advisories on the Application of California Law to AI
California Attorney General Rob Bonta issued two legal advisories clarifying that entities developing, selling, or using AI must comply with existing California consumer-protection, civil-rights, competition, data-privacy, and election-misinformation laws, plus new AI laws effective January 1, 2025, with a second advisory targeting healthcare entities.
-
In effect
NJ AG Platkin / DCR
NJ · Effective 2025-01-09 · NJ AG Platkin / DCR — Guidance on Algorithmic Discrimination and the NJLAD (2025-01-09)
13-page guidance affirming NJLAD applies to ADS-driven discrimination in employment, housing, credit, public accommodations. Launches Civil Rights and Technology Initiative and Civil Rights Innovation Lab.
-
In effect
Guidance on Algorithmic Discrimination and the New Jersey La
New Jersey · Effective 2025-01-09 · Guidance on Algorithmic Discrimination and the New Jersey Law Against Discrimination
AG Platkin and the Division on Civil Rights issued guidance clarifying that the NJ Law Against Discrimination applies to algorithmic discrimination from AI and automated decision tools, so covered entities can be liable for disparate treatment or disparate impact even without intent.
-
In effect
Executive Order No. 1584 (Fostering Stakeholder Collaboratio
Mississippi · Effective 2025-01-08 · Executive Order No. 1584 (Fostering Stakeholder Collaboration and Harnessing Artificial Intelligence)
Governor Tate Reeves directed the Department of Information Technology Services to inventory all state-agency AI, evaluate existing AI processes and procurement guidelines, and develop statewide responsible-AI policy recommendations.
-
In effect
IL Bar AI Standing Committee
IL · Effective 2025-01-01 · Ill. Sup. Ct. Policy on AI (eff. Jan. 1, 2025)
Illinois Supreme Court adopted a Policy on Artificial Intelligence (effective January 1, 2025) authorizing AI use by attorneys, judges, and court staff provided it complies with legal and ethical standards. The policy explicitly states that disclosure of AI use should not be required in a pleading, and does not impose mandatory CLE requirements; instead it supports ongoing education on AI and holds all users accountable for thoroughly reviewing AI-generated content before submission.
-
In effect
Nebraska NDPA
Nebraska · Effective 2025-01-01 · Neb. Rev. Stat. §§ 87-901 et seq. (LB 1074, 108th Leg., 2024), eff. Jan. 1, 2025
Nebraska's comprehensive consumer privacy law gives residents the right to access, correct, delete, and port their personal data and to opt out of targeted advertising, data sales, and automated profiling used in decisions with significant legal or financial effects. The Attorney General enforces with fines up to $7,500 per violation with no private right of action.
-
In effect
NH Consumer Privacy Act
New Hampshire · Effective 2025-01-01 · RSA 507-H (2024 NH SB 255)
New Hampshire residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions. Applies at low thresholds (35,000 residents), so it covers many businesses.
-
In effect
Delaware Privacy Law (DPDPA)
Delaware · Effective 2025-01-01 · 6 Del. C. § 12D-101 et seq. (2023 DE HB 154)
Delaware residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions with legal effects. Applies at low thresholds (35,000 consumers).
-
In effect
OR AG Rosenblum
OR · Effective 2024-12-24 · OR AG Rosenblum — AI Guidance (UTPA, OCPA, Equality Act) (2024-12-24)
Clarifies that Oregon's UTPA, OCPA, and Equality Act apply to AI absent AI-specific law. Misrepresenting AI capabilities, discriminatory outcomes, and processing biometric/sensitive data without consent are actionable.
-
In effect
NC DOI AI Bulletin
NC · Effective 2024-12-18 · North Carolina DOI Bulletin 24-B-19 (2024-12-18)
The NC Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NC must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Texas A&M System Regulation 29.01.05, Artificial Intelligenc
Texas A&M University System · Effective 2024-12-10 · Texas A&M System Regulation 29.01.05, Artificial Intelligence
The Texas A&M University System's AI regulation governs all AI activities system-wide, requiring AI inventories, data classification, bias audits, safeguards against algorithmic discrimination, and academic-integrity citation rules.
-
In effect
MA DOI AI Bulletin
MA · Effective 2024-12-09 · Massachusetts Division of Insurance Bulletin 2024-10 (2024-12-09)
The MA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in MA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Policy on the Responsible and Ethical Use of Artificial Inte
Nevada · Effective 2024-11-27 · Policy on the Responsible and Ethical Use of Artificial Intelligence in Nevada State Government Executive Branch
The Nevada CIO-signed policy sets minimum standards for responsible, ethical, and transparent AI use across executive-branch agencies, requiring risk-based assessments, procurement/contract controls, and continuous monitoring of AI tools.
-
In effect
OK DOI AI Bulletin
OK · Effective 2024-11-14 · Oklahoma ID Bulletin 2024-11 (2024-11-14)
The OK Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in OK must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
IA DOI AI Bulletin
IA · Effective 2024-11-07 · Iowa Insurance Division Bulletin 24-04 (2024-11-07)
The IA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in IA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Cruise SF Pedestrian Incident
CA · Effective 2024-10-31 · In re GM Cruise LLC — NHTSA Consent Order (Sept. 2024); confidential personal-injury settlement
A San Francisco pedestrian was struck by a hit-and-run driver, thrown into the path of a GM Cruise robotaxi, and then dragged ~20 feet by the Cruise vehicle in October 2023. NHTSA fined Cruise; the California PUC suspended its driverless permit; Cruise reached confidential settlement with the victim and ultimately shut down driverless robotaxi operations in 2024.
-
In effect
NY AG
NY · Effective 2024-10-17 · NY AG — Symposium Report on the Next Decade of AI (enforcement priorities) (2024-10-17)
James outlines enforcement priorities: hiring tool bias, GenAI misinformation, deepfakes, ADS. References LL144 precedent; previews state ADS guidance and legislative recommendations.
-
In effect
Texas v. Pieces Technologies
TX · Effective 2024-09-18 · Texas v. Pieces Technologies — Healthcare Generative AI Settlement (2024-09-18)
First state AG settlement targeting deceptive GenAI clinical marketing. Alleged Pieces misrepresented hallucination rates of a hospital summarization tool at four TX hospitals; settlement mandates accurate disclosures and monitoring. This action is an Assurance of Voluntary Compliance (AVC), not a monetary settlement; no penalty was assessed and Pieces Technologies denies wrongdoing.
-
In effect
Artificial Intelligence in Louisiana Schools: Guidance for K
Louisiana Department of Education (LDOE) · Effective 2024-08-28 · Artificial Intelligence in Louisiana Schools: Guidance for K-12 Schools
Louisiana's education department, acting on its AI Task Force recommendations, released K-12 AI guidance including a four-tier use system (AI-Empowered/Enhanced/Assisted/Prohibited) and a cyclical framework for policy, stakeholders, and monitoring.
-
In effect
WV DOI AI Bulletin
WV · Effective 2024-08-09 · West Virginia OIC Insurance Bulletin 24-06 (2024-08-09)
The WV Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in WV must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
MI DOI AI Bulletin
MI · Effective 2024-08-07 · Michigan DIFS Bulletin 2024-20-INS (2024-08-07)
The MI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in MI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
North Carolina State Government Responsible Use of Artificia
North Carolina · Effective 2024-08-01 · North Carolina State Government Responsible Use of Artificial Intelligence Framework
NCDIT published a NIST-based framework of principles, practices, and guidance for state agencies deploying AI while reducing privacy and data-protection risks to residents.
-
In effect
Colorado Roadmap for AI in K-12 Education
Colorado Department of Education · Effective 2024-08-01 · Colorado Roadmap for AI in K-12 Education
Colorado's education department (with the Colorado Education Initiative) published a statewide roadmap providing K-12 districts practical strategies and resources for integrating AI into teaching and learning.
-
In effect
AR DOI AI Bulletin
AR · Effective 2024-07-31 · Arkansas Insurance Department Bulletin 13-2024 (2024-07-31)
The AR Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in AR must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Empowering Lifelong Learning: AI Guidance for Enhancing K-12
Wisconsin Department of Public Instruction (DPI) · Effective 2024-07-29 · Empowering Lifelong Learning: AI Guidance for Enhancing K-12 and Library Education
Wisconsin's education department released 22-page guidance for K-12 classrooms and libraries covering core AI concepts, ethics/data policy, security, professional development, and curriculum integration.
-
In effect
VA DOI AI Bulletin
VA · Effective 2024-07-22 · Virginia SCC Bureau of Insurance Administrative Letter 2024-01 (2024-07-22)
The VA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in VA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Florida Digital Bill of Rights (privacy / profiling opt-out)
Florida · Effective 2024-07-01 · Fla. CS/CS/SB 262 (2023); ch. 2023-201, Laws of Fla.; Fla. Stat. Secs. 501.701-501.722
Florida's Digital Bill of Rights gives covered consumers a set of data-privacy rights, including the right to opt out of profiling carried out solely by automated processing when that profiling is used to make decisions that have a legal or similarly significant effect on the person. Businesses that meet the law's thresholds must also conduct and document data-protection assessments for higher-risk processing activities such as profiling, targeted advertising, and the sale of personal data. The Florida Attorney General enforces the law; consumers cannot sue directly. The law applies only to a relatively narrow set of very large businesses.
-
In effect
Maryland AI Governance Act (2024)
Maryland · Effective 2024-07-01 · 2024 Md. Laws ch. 496 (SB 818)
This law sets up a governance framework for how Maryland state government builds, buys, deploys, and uses artificial intelligence. Each state government unit must inventory the systems it uses that employ high-risk AI and conduct regular impact assessments. The Department of Information Technology is directed to develop and adopt policies covering the development, procurement, deployment, use, and ongoing assessment of high-risk AI systems.
-
In effect
New Hampshire HB 1688 (state-agency AI limits)
New Hampshire · Effective 2024-07-01 · N.H. HB 1688 (2024), effective July 1, 2024
New Hampshire set rules for how state agencies may use artificial intelligence. Agencies may not use AI to classify people in ways that cause unlawful discrimination, and they may not use real-time or remote biometric identification such as facial recognition to surveil public spaces — except by law enforcement acting under a warrant. Agencies also may not use deepfakes for deceptive or malicious purposes. When an AI recommendation cannot be reversed once carried out, a qualified human must review it first, AI-generated content must be disclosed, and the public must be told when they are interacting with AI.
-
In effect
Oregon SB 619 (opt out of profiling; child-data & assessment rules)
Oregon · Effective 2024-07-01 · Oregon Consumer Privacy Act, 2023 Or. Laws (SB 619), ORS 646A.570-646A.589, eff. July 1, 2024
Oregon's consumer privacy law lets residents opt out of having their personal data used for profiling that supports decisions with legal or similarly significant effects. It adds stronger protections for data about people the business knows are under 16, and requires businesses to complete and document data protection assessments for processing that poses a heightened risk, including risky profiling. The Attorney General enforces it; there is no private lawsuit right.
-
In effect
TDPSA
Texas · Effective 2024-07-01 · Tex. Bus. & Com. Code ch. 541 (HB 4, 2023)
Texans can access, correct, delete, and obtain copies of personal data held by covered businesses, and can opt out of targeted advertising, data sales, and profiling used for decisions with significant effects (like jobs, housing, or credit). Businesses must get consent for sensitive data, including biometrics.
-
In effect
Human-Centered AI Guidance for K-12 Public Schools
Washington Office of Superintendent of Public Instruction (OSPI) · Effective 2024-07-01 · Human-Centered AI Guidance for K-12 Public Schools
Washington's state superintendent issued 'Human-AI-Human' guidance for K-12 schools covering AI foundations, classroom implementation, ethical considerations, policy suggestions, and privacy compliance.
-
In effect
NE DOI AI Bulletin
NE · Effective 2024-06-11 · Nebraska Insurance Guidance Document IGD-H1 (2024-06-11)
The NE Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NE must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
DC DOI AI Bulletin
DC · Effective 2024-05-21 · DC DISB Bulletin 24-IB-002-05/21 (2024-05-21)
The DC Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in DC must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
SUNY generative-AI education initiative (Empire AI / systemw
State University of New York (SUNY) · Effective 2024-05-09 · SUNY generative-AI education initiative (Empire AI / systemwide AI chatbot program)
New York and SUNY launched a systemwide generative-AI education program described as the largest LLM-enabled education system, providing customized tutoring while pledging to protect privacy and academic integrity.
-
In effect
DC Bar Op. 388 (GenAI)
DC · Effective 2024-04-24 · D.C. Bar Op. 388 (Apr. 24, 2024)
DC lawyers using generative AI must understand the tools they use, supervise AI output, protect client confidentiality, communicate with clients about AI, comply with billing rules, and avoid the unauthorized practice of law by AI chatbots.
-
In effect
MD DOI AI Bulletin
MD · Effective 2024-04-22 · Maryland Insurance Administration Bulletin 24-11 (2024-04-22)
The MD Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in MD must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
WA DOI AI Bulletin
WA · Effective 2024-04-22 · Washington OIC Technical Assistance Advisory 2024-02 (2024-04-22)
The WA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in WA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
MA AG Campbell
MA · Effective 2024-04-16 · MA AG Campbell — Advisory on Consumer Protection, Anti-Discrimination, Data Security and AI (2024-04-16)
Clarifies that Chapter 93A, the Anti-Discrimination Law, and MA Data Security Regs apply fully to AI developers, suppliers, and users; identifies algorithmic discrimination and misrepresenting AI capabilities as unfair/deceptive.
-
In effect
KY DOI AI Bulletin
KY · Effective 2024-04-16 · Kentucky DOI Bulletin 2024-02 (2024-04-16)
The KY Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in KY must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Huang v. Tesla
CA · Effective 2024-04-08 · Huang v. Tesla, Inc., No. 19CV346663 (Cal. Super. Ct. Santa Clara Cty.)
Apple engineer Walter Huang died in 2018 when his Tesla Model X on Autopilot crashed into a highway divider. His family sued; the case settled confidentially on the eve of trial in April 2024 — the first Autopilot wrongful-death case to reach (and settle on the eve of) a jury verdict.
-
In effect
NY Bar AI Report
NY · Effective 2024-04-06 · NYSBA AI Task Force Report (Apr. 6, 2024)
The New York State Bar adopted recommendations on AI in legal practice covering competence, confidentiality, supervision, candor to the court, and advertising — explicitly noting that 'hallucination' sanctions in Mata v. Avianca apply to all New York lawyers using AI.
-
In effect
PA DOI AI Bulletin
PA · Effective 2024-04-06 · Pennsylvania ID Insurance Notice 2024-04 (54 Pa.B. 1910) (2024-04-06)
The PA Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in PA must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Artificial Intelligence: Guidance for K-12 Classrooms
Mississippi Department of Education (MDE) · Effective 2024-04-05 · Artificial Intelligence: Guidance for K-12 Classrooms
Mississippi's education department published procedural guidance and instructional strategies for district and school leaders and teachers on appropriate AI use, including definitions, classroom impact, and policy-development considerations.
-
In effect
NJ TRANSIT AI Video-Analytics Grade-Crossing Safety System (
New Jersey Transit (NJ TRANSIT) · Effective 2024-04-01 · NJ TRANSIT AI Video-Analytics Grade-Crossing Safety System (federal grant with Rutgers CAIT)
NJ TRANSIT received a $1.6M USDOT grant to develop, with Rutgers CAIT, a deep-learning video-analytics system that monitors light-rail grade crossings to detect safety events and trespassers.
-
In effect
RI DOI AI Bulletin
RI · Effective 2024-03-15 · Rhode Island DBR Insurance Bulletin 2024-03 (2024-03-15)
The RI Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in RI must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
IL DOI AI Bulletin
IL · Effective 2024-03-13 · Illinois DOI Company Bulletin 2024-08 (2024-03-13)
The IL Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in IL must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
VT DOI AI Bulletin
VT · Effective 2024-03-12 · Vermont DFR Insurance Bulletin 229 (2024-03-12)
The VT Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in VT must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Executive Order 24-06: Artificial Intelligence and Data Cent
Rhode Island · Effective 2024-02-29 · Executive Order 24-06: Artificial Intelligence and Data Centers of Excellence
Governor Dan McKee's executive order establishes an AI Task Force, an AI Center of Excellence and a Data Center of Excellence, and directs the Department of Administration to develop a state code of ethics for AI and secure AI adoption across state agencies.
-
In effect
CT DOI AI Bulletin
CT · Effective 2024-02-26 · Connecticut Insurance Department Bulletin MC-25 (2024-02-26)
The CT Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in CT must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
NV DOI AI Bulletin
NV · Effective 2024-02-23 · Nevada DOI Bulletin 24-001 (2024-02-23)
The NV Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NV must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
NH DOI AI Bulletin
NH · Effective 2024-02-20 · New Hampshire ID Docket INS 24-011-AB (2024-02-20)
The NH Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in NH must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
Mayor's Order 2024-028: Articulating DC's Artificial Intelli
District of Columbia · Effective 2024-02-08 · Mayor's Order 2024-028: Articulating DC's Artificial Intelligence Values and Establishing Artificial Intelligence Strategic Benchmarks
Mayor Bowser's order defines six AI values (clear benefit to the people, safety & equity, accountability, transparency, sustainability, and privacy & cybersecurity), establishes an AI Advisory Group and AI Taskforce, and requires District agencies to verify AI-values alignment before deploying any AI tool.
-
Proposed / pending
OCTO AI/ML Governance Policy
District of Columbia · Effective 2024-02-08 · OCTO AI/ML Governance Policy
The Office of the Chief Technology Officer's governance policy establishes rules for the responsible and secure use of AI/ML in DC government, requiring written agency-director approval before using agency data with AI, cybersecurity and business risk assessments, use of only OCTO-approved platforms, data-classification restrictions, and continuous monitoring.
-
In effect
AK DOI AI Bulletin
AK · Effective 2024-02-01 · Alaska Division of Insurance Bulletin B 24-01 (2024-02-01)
The AK Department of Insurance adopted the NAIC Model Bulletin on Use of Artificial Intelligence Systems by Insurers. Insurers licensed in AK must maintain a written AI program with governance, risk-management, testing, third-party-AI oversight, and documentation controls. The bulletin operationalizes existing unfair-trade-practice and unfair-discrimination law as applied to insurers' AI use cases — underwriting, pricing, claims, fraud detection, and marketing.
-
In effect
CA AG Bonta
CA · Effective 2024-01-26 · CA AG Bonta — CCPA Investigative Sweep of Streaming Services (2024-01-26)
Sweep into streaming services' opt-out compliance; led to a $530K Sling TV settlement in 2025 and parallel CPPA actions (Honda $632,500) on ADMT-adjacent practices.
-
In effect
NJ Supreme Court GenAI Notice
NJ · Effective 2024-01-25 · NJ Supreme Court Notice (Jan. 25, 2024)
The New Jersey Supreme Court issued a binding notice requiring lawyers using generative AI to comply with the Rules of Professional Conduct, including verifying citations, protecting client confidentiality, and supervising AI output. Sanctions follow citation hallucination.
-
In effect
FL Bar Op. 24-1 (GenAI)
FL · Effective 2024-01-19 · Fla. Bar Ethics Op. 24-1
Florida lawyers using generative AI must obtain informed client consent before using AI to handle client information, supervise AI like nonlawyer staff, verify factual and legal accuracy, comply with advertising rules for AI chatbots, and follow billing requirements that prevent overcharging.
-
In effect
NC Generative AI Implementation Recommendations and Consider
North Carolina Department of Public Instruction (NCDPI) · Effective 2024-01-16 · NC Generative AI Implementation Recommendations and Considerations for PK-13 Public Schools
North Carolina's education department released a generative AI guidebook (including the 'EVERY' responsible-use framework) covering leadership, human capacity, curriculum, data privacy, and technology infrastructure for public schools.
-
In effect
Acceptable Use of Artificial Intelligence Technologies (NYS-
New York · Effective 2024-01-08 · Acceptable Use of Artificial Intelligence Technologies (NYS-P24-001)
New York's Office of Information Technology Services set enterprise rules requiring state agencies to conduct NIST-based risk assessments, maintain human oversight of AI decisions affecting the public, and disclose AI chatbots as non-human.
-
In effect
California AB 302 (state must inventory its high-risk automated decision systems)
California · Effective 2024-01-01 · Cal. Gov. Code 11546.45.5 (AB 302, Stats. 2023)
California directs its Department of Technology to compile a comprehensive inventory of the high-risk automated decision systems that state agencies use, develop, or buy. A high-risk system is one that helps make or replaces consequential decisions affecting things like housing, jobs, credit, health care, education, and criminal justice. The Department must report the inventory to the Legislature annually, with the obligation winding down at the start of 2029.
-
In effect
State of Indiana Artificial Intelligence Policy
Indiana · Effective 2024-01-01 · State of Indiana Artificial Intelligence Policy
Indiana's state AI policy, issued by the Office of the Chief Data Officer, applies the NIST AI Risk Management Framework and requires agencies to submit an AI Readiness Assessment Questionnaire and report existing AI systems before use.
-
In effect
Enterprise Artificial Intelligence Policy (200-POL-007)
Tennessee · Effective 2024-01-01 · Enterprise Artificial Intelligence Policy (200-POL-007)
Tennessee's Department of Finance and Administration (Strategic Technology Solutions) sets minimum requirements for valid, reliable, transparent, and ethical use of AI across state departments, requiring monitoring of AI design, deployment, and procurement to minimize negative impacts.
-
In effect
CCC systemwide AI guidance and HUMANS responsible-AI framewo
California Community Colleges Chancellor's Office · Effective 2024-01-01 · CCC systemwide AI guidance and HUMANS responsible-AI framework
The California Community Colleges Chancellor's Office issues systemwide AI guidance built on its HUMANS framework (human-centered, privacy, algorithmic-discrimination protections, notice and explanation, safety) governing AI in instruction and student support.
-
In effect
Penn State systemwide Generative AI Guidelines
Pennsylvania State University (Penn State) · Effective 2024-01-01 · Penn State systemwide Generative AI Guidelines
Penn State's systemwide AI guidelines set responsible-use rules covering FERPA/HIPAA compliance, output verification, accessibility review of AI tools, disclosure, and restrictions on AI-assisted grading across its multi-campus system.
-
In effect
Use of Artificial Intelligence (AI) in State of Ohio Solutio
Ohio · Effective 2023-12-04 · Use of Artificial Intelligence (AI) in State of Ohio Solutions (Policy IT-17)
Ohio's Department of Administrative Services adopted Policy IT-17 requiring state AI use to be fair, accountable, transparent, and human-centric, mandating piloting, human verification for consequential decisions, and limiting generative-AI inputs to public-record data.
-
In effect
CA Bar GenAI Guidance
CA · Effective 2023-11-16 · State Bar of California, COPRAC Practical Guidance (Nov. 16, 2023)
California lawyers using ChatGPT, CoPilot, or other generative AI tools must protect client confidentiality, verify AI-generated work, supervise AI outputs, disclose AI use where required, and avoid billing for time saved by AI. Misuse of generative AI is a discipline-eligible violation.
-
In effect
Generative Artificial Intelligence (AI) in K-12 Classrooms G
Oregon Department of Education · Effective 2023-11-01 · Generative Artificial Intelligence (AI) in K-12 Classrooms Guidance
Oregon's education department maintains generative AI guidance and a companion 'Developing Policy and Protocols' document to help districts adopt safe, ethical, equitable AI policies in K-12 classrooms.
-
In effect
PA EO 2023-19 (GenAI)
PA · Effective 2023-09-20 · Pa. Exec. Order No. 2023-19 (Sept. 20, 2023)
Governor Shapiro's EO 2023-19 establishes Pennsylvania's Generative AI Governing Board and sets 10 core values (accuracy, adaptability, employee empowerment, equity and fairness, innovation, mission alignment, privacy, proportionality, safety and security, and transparency) that govern Commonwealth agencies' use of generative AI tools.
-
In effect
State of Kansas Generative Artificial Intelligence Policy (P
Kansas · Effective 2023-07-31 · State of Kansas Generative Artificial Intelligence Policy (PPM 8200.00)
The Kansas Office of Information Technology Services enterprise policy sets acceptable-use rules for generative AI, requiring human review of all AI outputs, barring Restricted Use Information from AI tools, and imposing vendor disclosure and data-control requirements.
-
In effect
Colorado Privacy Act (CPA)
Colorado · Effective 2023-07-01 · Colo. Rev. Stat. Sec. 6-1-1301 et seq. (SB 21-190)
The Colorado Privacy Act gives state residents the right to opt out of having their personal data used for profiling when that profiling drives decisions that produce legal or similarly significant effects, such as decisions about credit, housing, employment, or services. Businesses that engage in higher-risk processing, including certain profiling, must conduct and document a data protection assessment weighing the benefits against the risks. The Colorado Attorney General enforces the law, and since January 1, 2025 may bring actions without first offering a chance to cure.
-
In effect
CT SB 1103 (state-government AI oversight)
Connecticut · Effective 2023-07-01 · 2023 Conn. Public Acts 23-16 (SB 1103)
This law sets rules for how Connecticut's own state government uses artificial intelligence. It directs the Department of Administrative Services to catalog the AI systems that state agencies use and to assess them for unlawful discrimination and disparate impact. It also establishes an AI officer in the Office of Policy and Management to develop AI policies and procedures that agencies must follow. The law governs public-sector use rather than imposing penalties on private companies.
-
In effect
Connecticut Data Privacy Act (CTDPA) (profiling opt-out)
Connecticut · Effective 2023-07-01 · Conn. Gen. Stat. Sec. 42-515 to 42-525; P.A. 22-15
Connecticut's consumer privacy law lets residents opt out of having their personal data used for profiling that feeds automated decisions carrying legal or similarly significant effects. Businesses that profile consumers for high-risk purposes must also run data protection assessments to weigh the risks. Other consumer rights include access, correction, deletion, and opting out of targeted advertising and data sales. The Attorney General enforces the law under Connecticut's unfair trade practices framework, and there is no individual right to sue.
-
In effect
Virginia VCDPA (opt out of profiling, $7,500/violation)
Virginia · Effective 2023-01-01 · Va. Code 59.1-575 to 59.1-585 (esp. 59.1-577, 59.1-580, 59.1-584); HB 2307 / SB 1392 (2021)
Virginia's comprehensive privacy law gives consumers the right to opt out of 'profiling' used to make decisions producing legal or similarly significant effects, such as automated decisions affecting credit, housing, employment, or essential services. Businesses must obtain heightened consent before processing the data of a known child (via federal COPPA) and must conduct documented data protection assessments for higher-risk processing, including certain profiling. The Attorney General enforces the law and may seek up to $7,500 per violation; there is no private right of action.
-
In effect
PA Act 130 of 2022 (HAVs)
Pennsylvania · Effective 2022-11-03 · Act 130 of 2022; 75 Pa. C.S. Ch. 88
Pennsylvania's comprehensive AV law authorized fully driverless operation, created a PennDOT permitting regime for testing and commercial deployment, required incident reporting to PennDOT and State Police, and authorized 'highly automated work zone vehicles' and platooning. Pennsylvania had been an AV testing hub since 2016 under non-statutory PennDOT guidance; Act 130 finally codified the framework.
-
In effect
SEPTA ZeroEyes AI Gun-Detection Pilot Program
Southeastern Pennsylvania Transportation Authority (SEPTA) · Effective 2022-11-01 · SEPTA ZeroEyes AI Gun-Detection Pilot Program
SEPTA's board approved a ZeroEyes AI gun-detection pilot layered on its 30,000+ cameras to flag brandished firearms within seconds, but the year-long pilot was ended after the aging analog camera infrastructure proved incompatible.
-
In effect
OH HB 7 (2022 AV)
Ohio · Effective 2022-09-13 · Ohio Rev. Code §§ 4501.01, 4511.01, 4511.991
Ohio's 2022 statute codified what had been executive-order policy under DriveOhio: fully driverless AV operation is allowed, the registered owner is the legal operator for traffic enforcement, AV networks must carry $5 million in insurance, and the state must maintain an AV testing program (the Smart Mobility / TRC framework).
-
In effect
Vermont H.410 / Act 132 (inventory of state AI / automated decision systems)
Vermont · Effective 2022-07-01 · 2022 Vt. Acts & Resolves No. 132 (H.410); 3 V.S.A. 3305
Vermont directed its Agency of Digital Services to review and catalog every automated decision system the state is building, using, or buying. The inventory must document each system's name, vendor, capabilities, data inputs, whether it was tested for bias, its intended purpose, and its costs, covering both systems that decide on their own and those that assist a human. The law also created state AI governance bodies, including a Division of Artificial Intelligence and an AI Advisory Council.
-
In effect
UC Responsible AI Principles and AI Council governance frame
University of California (UC System) · Effective 2021-10-01 · UC Responsible AI Principles and AI Council governance framework
UC was the first US university system to adopt Responsible AI Principles and stand up a systemwide AI Council that issues guidance, training, and risk assessments for AI use across its campuses.
-
In effect
CO Insurance Algorithmic Discrimination Law
Colorado · Effective 2021-07-06 · Colo. Rev. Stat. Sec. 10-3-1104.9 (SB 21-169)
Colorado prohibits insurers from using outside consumer data, algorithms, or predictive models in ways that unfairly discriminate against people based on protected characteristics such as race, sex, religion, sexual orientation, disability, or gender identity. The law directs the state Insurance Commissioner to write rules that require insurers to test their data and models and show they do not produce discriminatory outcomes. Insurers must also maintain a risk-management framework to monitor for unfair discrimination. Coverage was later expanded to additional lines such as private passenger auto and health benefit plans.
-
In effect
AI Video Interview Act
Illinois · Effective 2020-01-01 · 820 ILCS 42/1 et seq.
Employers using AI to analyze video interviews of Illinois job applicants must tell applicants beforehand, explain how the AI works, get consent, limit video sharing, and delete videos on request within 30 days. Employers relying solely on AI screening must report applicant demographic data to the state.
-
In effect
AR Act 1096 (2019 AV)
Arkansas · Effective 2019-07-24 · Act 1096 of 2019; Ark. Code Ann. §§ 27-51-1801 et seq.
Arkansas authorized commercial driver-assistive truck platooning and limited driverless AV pilots, established a Pilot Program for Driverless-Capable Vehicles administered by the Arkansas State Highway Commission, and required pilots to file insurance and incident-reporting plans.
-
In effect
UT HB 101 (2019 AV statute)
Utah · Effective 2019-05-14 · Utah Code §§ 41-26-101 et seq.
Utah's AV law expressly allows fully driverless operation, treats the automated driving system as the 'driver' for traffic-law purposes, authorizes commercial AV networks, and preempts local AV regulation.
-
In effect
NE LB 989 (2018 AV)
Nebraska · Effective 2018-04-25 · Neb. Rev. Stat. §§ 60-3,201 et seq.
Nebraska's Driverless-Capable Vehicle Act explicitly allows fully driverless operation on Nebraska public roads, treats the automated driving system as the driver for traffic-law purposes, sets minimum insurance ($5 million for on-demand AV networks), and preempts local regulation.
-
In effect
AZ EO 2018-04 (AV oversight)
Arizona · Effective 2018-03-01 · Ariz. Exec. Order No. 2018-04
On March 1, 2018 — 17 days before the fatal Uber self-driving crash in Tempe — Governor Doug Ducey issued EO 2018-04 to update his permissive 2015 AV order and advance Arizona's position as a national leader for autonomous vehicle development. The order requires AV operators to certify compliance with federal and state law before operating in Arizona and to file safety information with the DOT. After the Uber crash on March 18, 2018, Ducey separately suspended Uber's testing privileges by letter rather than by executive order. Arizona's AV regime remains executive-order based, with no comprehensive statute.
-
In effect
CT Rideshare Dynamic-Pricing Law (surge-price limits)
Connecticut · Effective 2018-01-01 · Conn. Gen. Stat. Sec. 13b-118; Sec. 13b-117 (penalty); P.A. 17-140
When a ride-hailing company (like Uber or Lyft) uses dynamic or 'surge' pricing, Connecticut law requires it to warn riders before they request a ride, give them a tool to estimate the fare, and make them confirm they understand surge pricing will apply. The law also caps price gouging during emergencies: a company cannot charge more than 2.5 times its usual fare in any area covered by a declared disaster emergency. The state transportation commissioner oversees TNC registration and can suspend or revoke it for violations. Operating without a valid registration can draw a substantial fine.
-
In effect
NC HB 469 (2017 AV statute)
North Carolina · Effective 2017-12-01 · S.L. 2017-166; N.C. Gen. Stat. §§ 20-400–20-403
North Carolina legalized fully autonomous vehicles, treats the registered owner as the operator for traffic-enforcement purposes, allows AVs to transport unaccompanied minors only with parental consent, and preempts local AV regulation.
-
In effect
TX SB 2205 (2017 AV statute)
Texas · Effective 2017-09-01 · Tex. Transp. Code §§ 545.451–545.456
Texas's main autonomous-vehicle law explicitly authorizes AVs to operate on Texas roads without a human driver, defines the 'owner' of an automated driving system as the legal operator for liability and traffic enforcement, and preempts local AV bans. It set the framework that later allowed Waymo, Cruise, and Aurora freight to operate in Texas.
-
In effect
GA SB 219 (2017 AV statute)
Georgia · Effective 2017-07-01 · 2017 Ga. Laws Act 245
Georgia legalized fully driverless autonomous vehicles statewide, required AVs to be registered, insured ($250,000 minimum for fully autonomous vehicles), and capable of complying with traffic laws. The statute preempts local AV-specific ordinances.
-
In effect
TN SB 151 (2017 AV Act)
Tennessee · Effective 2017-07-01 · 2017 Tenn. Pub. Acts Ch. 474; Tenn. Code Ann. §§ 55-30-101 et seq.
Tennessee's Automated Vehicles Act authorized fully driverless operation on Tennessee roads, set minimum-insurance requirements for AV networks ($5 million coverage), explicitly preempted local AV-specific regulation, and treated the automated driving system as the legal operator for traffic-law purposes.
-
In effect
CO SB 17-213 (AV statute)
Colorado · Effective 2017-06-01 · Colo. Rev. Stat. § 42-4-242
Colorado authorized automated driving systems, allowing AVs that can comply with all traffic laws to operate without a separate state authorization — but if the ADS cannot fully comply, the operator must coordinate with CDOT and the State Patrol before deployment.
-
In effect
NY AV testing pilot
New York · Effective 2017-04-20 · Part FF, Ch. 55, Laws of 2017 (uncodified session law)
New York requires AV operators to obtain DMV pilot-program authorization, maintain a licensed human safety driver behind the wheel, post a $5 million insurance bond, and coordinate with State Police for each test deployment. New York remains one of the most restrictive states — fully driverless operation is not authorized as of 2026.
-
In effect
MI SAVE Acts (2016 AV package)
Michigan · Effective 2016-12-09 · P.A. 332–335 of 2016
Michigan's 2016 four-bill 'SAVE' package made the state one of the most comprehensive AV jurisdictions: it legalized fully driverless operation, authorized commercial AV networks (ride-hail with self-driving cars), allowed truck platooning, established the American Center for Mobility, and explicitly limited manufacturer liability when third parties convert vehicles to autonomous operation.
-
In effect
FL HB 7027 (2016 driverless AV)
Florida · Effective 2016-04-04 · Ch. 2016-181, Laws of Fla.; Fla. Stat. §§ 316.85, 316.86
Florida became one of the first states to allow fully driverless autonomous vehicles on public roads. HB 7027 removed the prior requirement that a licensed driver be present in the vehicle and built on Florida's 2012 AV testing law, paving the way for the 2019 'driverless deployment' law (HB 311) that explicitly authorizes AVs with no human driver.
-
In effect
CA SB 1298 (2012 AV authorization)
California · Effective 2013-01-01 · Cal. Veh. Code §§ 38750 et seq.
California's foundational autonomous-vehicle statute. SB 1298 directed the DMV to adopt regulations for testing and eventual deployment of AVs on California roads, including an autonomous-vehicle tester permit, insurance and bonding rules, and the framework later used for the Cruise and Waymo robotaxi authorizations.
-
In effect
NV AB 511 (2011 — first AV statute)
Nevada · Effective 2011-06-17 · NRS Ch. 482A (2011 Nev. Stat. Ch. 461)
Nevada was the first U.S. state to legalize autonomous vehicles. AB 511 directed the DMV to write rules for testing and operating self-driving cars on Nevada roads, including a special license endorsement and an autonomous-vehicle testing license, and made Nevada the proving ground for the early Google self-driving project.
-
Proposed / pending
House Bill 2512 — Banning surveillance pricing by rideshare
Pennsylvania · House Bill 2512 — Banning surveillance pricing by rideshare companies
Pennsylvania's House passed HB 2512 to prohibit transportation network companies (Uber/Lyft) from using consumers' personal data to set individualized 'surveillance' prices, now advancing to the Senate.
-
Vetoed
Arizona HB 2592 AI state agencies — vetoed 2026
Arizona · Ariz. H.B. 2592, 57th Leg., 2d Reg. Sess. (2026) — vetoed June 19, 2026
Arizona HB 2592 would have required every state agency to identify opportunities to implement AI systems that reduce administrative burdens, eliminate regulations restricting AI adoption, streamline AI procurement, and establish internal AI governance policies. The bill passed the House 35-20 and the Senate 16-12 with bipartisan support, but Governor Katie Hobbs vetoed it on June 19, 2026, writing that state agencies were already weighing AI adoption and the bill was redundant. It was one of three AI bills — and 88 total bills — vetoed by Hobbs on the same day.
-
Repealed / replaced
Colorado AI Act (repealed)
Colorado · SB 24-205, Colo. Rev. Stat. § 6-1-1701 et seq. (repealed/replaced 2026)
The first comprehensive US state AI law would have required developers and deployers of 'high-risk' AI systems to use reasonable care to prevent algorithmic discrimination in decisions about jobs, housing, lending, insurance, education, and healthcare. After repeated delays, it was repealed and replaced in May 2026 by a narrower transparency-focused law (SB 26-189) before it ever took effect.
-
Proposed / pending
MTA AI Video Analytics Solicitation for Subway Camera Monito
New York Metropolitan Transportation Authority (MTA) · MTA AI Video Analytics Solicitation for Subway Camera Monitoring (Suspicious/Problematic Behavior Detection)
The MTA solicited vendors for AI computer-vision software to analyze feeds from its 15,000+ subway cameras to flag weapons, unattended items, and dangerous behavior, while stating facial recognition will not be used.
-
Proposed / pending
MTA/NYPD Evolv AI Weapons-Detection Scanner Pilot in NYC Sub
Metropolitan Transportation Authority / NYPD subway weapons scanners · MTA/NYPD Evolv AI Weapons-Detection Scanner Pilot in NYC Subway
The MTA and NYPD piloted Evolv AI-powered gun-detection scanners at NYC subway stations; a monthlong test of 3,000+ searches at 20 stations found no guns and over 100 false positives.
-
Vetoed
PR P. de la C. 347 (vetoed)
Puerto Rico · P. de la C. 347 (19th Leg. Assembly); pocket vetoed Nov. 12, 2024
House bill that would have authorized PRITS to regulate Executive Branch AI use with administrative penalties of $2,500–$10,000 for noncompliance. Pocket vetoed by Governor Pierluisi on November 12, 2024 — so there is no PR-wide statutory AI penalty regime yet.
-
Proposed / pending
PR P. del S. 731 (AI Public Procurement Law)
Puerto Rico · P. del S. 731 (19th Leg. Assembly); Puerto Rico Senate approval ~May 28–30, 2026
Puerto Rico Senate Bill 731 would create the 'Law of Public Procurement with Artificial Intelligence of Puerto Rico,' centralizing all government purchases and public auctions under the General Services Administration and mandating use of the Joint E-Procurement Digital Intelligence (JEDI) AI platform across all government entities covered by Law 73-2019. JEDI automates procurement workflows, official publications, and incorporates all eight acquisition methods recognized by law. Approved by the Puerto Rico Senate in late May 2026; pending the House of Representatives and governor.
-
Proposed / pending
NJ Kids Code Act A4015 (2026)
NJ · N.J. A4015/S3413 (222nd Legislature, 2026) — cleared both chambers June 30, 2026; enrolled to governor
New Jersey A4015/S3413, the NJ Kids Code Act, is an Age-Appropriate Design Code bill modeled on the UK ICO Children's Code and California AB 2273 (CAADCA). It requires online platforms and services likely to be accessed by children under 18 to conduct data protection impact assessments, default privacy settings to the highest protective level for minor users, prohibit profiling children for commercial purposes without parental consent, and restrict design features that extend children's engagement. The Assembly cleared it 73-5-0; the Senate cleared it; enrolled to Governor Sherrill as of July 1, 2026. Governor Sherrill has not yet signed.
-
Proposed / pending
Algorithmic rent price-fixing ban
Illinois · IL SB343 (104th General Assembly, 2025-2026)
Would amend the Illinois Antitrust Act to ban landlords from using shared rent-setting algorithms or third-party pricing software (such as RealPage) to coordinate residential rental prices. Targets "algorithmic" or "AI-enabled" rent price-fixing, where competing landlords feed data into a common service that recommends prices, indirectly coordinating rents across the market. Prohibits fixing, controlling, or maintaining rental pricing or terms for residential units, including through any service or product that involves price coordination.
-
Proposed / pending
SB1077
MI · MI SB1077 (103rd Legislature)
Labor: fair employment practices; use of electronic monitoring or automated decisions tools by an employer; prohibit except for certain purposes. Creates new act.
-
Proposed / pending
A10909
NY · NY A10909 (2025-2026 General Assembly)
Enacts the "Shirley Myers White Right To Reconciliation and Digital Identity Repair Act"; establishes a right for individuals to have outdated, inaccurate, or incomplete public and digital narratives corrected once a legal matter is resolved; requires institutions to provide mechanisms for context, updates, and correction so that individuals are not permanently penalized by disproven or obsolete information in digital and automated systems.
-
Proposed / pending
HB2678
PA · PA HB2678 (2025-2026 Regular Session)
An Act amending Title 63 (Professions and Occupations (State Licensed)) of the Pennsylvania Consolidated Statutes, in powers and duties, further providing for definitions and providing for artificial intelligence.
-
Proposed / pending
HB2666
PA · PA HB2666 (2025-2026 Regular Session)
An Act providing for limitations on the use of user data in the creation of artificial intelligence simulations and for private right of action; and imposing penalties.
-
Proposed / pending
HB2669
PA · PA HB2669 (2025-2026 Regular Session)
An Act providing for employer disclosure when employee layoffs occur due to an employer's use of artificial intelligence or other technological change; and imposing civil penalties.
-
Expired
SB239
SD · SD SB239 (2026 Regular Session)
Modify provisions relating to the reinvestment payment program, and relating to the purchasing of goods and services used by projects approved for the reinvestment payment program.
-
Proposed / pending
HJ 4
MT · MT HJ 4
Interim study of artificial intelligence
-
Proposed / pending
PR P. del S. 68 (Gov AI Framework)
Puerto Rico · P. del S. 68 (19th Leg. Assembly)
Senate bill creating a Chief AI Officer position at PR Innovation and Technology Service (PRITS) plus an AI Advisory Committee. Would govern PR government use of AI, require non-discrimination assessments, and mandate annual reports. Cleared Senate; pending House vote.
-
Repealed / replaced
CO SB24-205 (original)
CO · Effective 2026-02-01 · Colo. SB 24-205 (2024) — substantially superseded by SB 26-189 (May 14, 2026)
Colorado SB24-205 was the first U.S. comprehensive high-risk AI statute (2024). The original framework was substantially rewritten by SB 26-189 after the 2026 special session — this entry is the historical record of the original law.
-
Repealed / replaced
CCPA Original (AB 375, 2018)
CA · Effective 2020-01-01 · Cal. AB 375 (2018), 2018 Cal. Stats. ch. 55 — substantially superseded by Prop 24 (CPRA) and 2025 CPPA ADMT regs
Governor Jerry Brown signed AB 375 — the original California Consumer Privacy Act — on June 28, 2018, the most comprehensive state privacy law in U.S. history at the time. Substantially amended by Prop 24 (CPRA, 2020) and the 2025 CPPA ADMT regulations. This entry captures the original 2018 framework as historical baseline.
-
Expired
AK HB 358 — deepfake defamation / electioneering (dead, 2024)
Alaska · AK HB 358 (33rd Alaska Legislature, 2023-2024)
A 2023-2024 Alaska House bill that would have created defamation claims based on the use of deepfakes and regulated the use of deepfakes in electioneering communications. It passed the House but died without becoming law: the 33rd Alaska Legislature adjourned on May 15, 2024 with the bill stalled in the Senate Rules Committee. This entry is kept only as a historical record of a dead bill — it is NOT a law in effect and does not protect anyone today. The same subject matter is being pursued in the current 34th Legislature as AK SB 33.
-
Expired
NY S3971B (2019, AI study commission, died)
NY · N.Y. S3971B (2019-20 Reg. Sess.) — died in Assembly
New York S3971B (Savino, 2019) would have created a temporary state commission to study AI regulation across New York agencies. Died in the Assembly Governmental Operations committee — but the commission framework became the model for later state AI task force statutes nationwide.
-
Vetoed
CA SB 1047 (vetoed)
CA · Cal. SB 1047 (2023-24 Reg. Sess.) — vetoed Sept. 29, 2024
California SB 1047 would have required safety testing, kill-switches, and developer liability for frontier AI models trained above compute/cost thresholds. Governor Newsom vetoed it on September 29, 2024 — a landmark veto that reshaped the U.S. frontier-AI policy debate.
-
Vetoed
VA HB 2094 (vetoed)
VA · Va. HB 2094 (2025) — vetoed Mar. 24, 2025
Virginia HB 2094 would have imposed Colorado-style duties on developers and deployers of high-risk AI systems with consumer disclosures and impact assessments. Governor Youngkin vetoed it on March 24, 2025 — the first red-state veto of an EU-AI-Act-style framework.
-
Expired
CA AB 2930 (died)
CA · Cal. AB 2930 (2023-24 Reg. Sess.) — held on suspense file Aug. 31, 2024
California AB 2930 (Bauer-Kahan) would have imposed algorithmic-discrimination duties on developers and deployers of automated decision tools used for consequential decisions. Held on Senate Appropriations suspense file in August 2024 — never received floor vote.
-
Expired
CT SB 2 (died)
CT · Conn. SB 2 (2024 Reg. Sess.) — died in House
Connecticut SB 2 was a comprehensive AI bill mirroring Colorado SB24-205. Passed the Senate in 2024 but was never called for a House vote after Governor Lamont opposition over potential business impact.
-
Expired
NY S7623B (died)
NY · N.Y. S7623B (2023-24 Reg. Sess.) — died in committee
New York S7623B was a comprehensive AI rights and disclosure bill. Never advanced past the Senate Internet committee in 2024.
County automated decision-making rules (29)
-
In effect
Wasatch County UT AI use policy (Jul. 15, 2026)
Wasatch County, UT · Effective 2026-07-15 · Wasatch County, UT Council unanimous vote, July 15, 2026, adopting county government AI use policy
Wasatch County, Utah unanimously adopted a policy on July 15, 2026 setting guardrails for county government use of artificial intelligence. The policy restricts county employees to approved AI tools only, requires disclosure when AI is used, and requires human verification of AI-generated output before it is relied on. The policy governs internal county government use of AI rather than regulating private-sector AI.
-
In effect
Montgomery County PA Generative AI Governance Policy
Montgomery County, PA · Effective 2025-11-18 · Montgomery County PA Commissioners policy (2025) (2025-11-18)
Montgomery County PA (Norristown) adopted AI governance policy: bars PII/PHI in public LLMs, requires CIO approval for AI procurement, mandates inventory of AI tools, and requires impact review before deployment in benefits or eligibility contexts.
-
In effect
Allen County IN County AI Use Policy
Allen County, IN · Effective 2025-11-04 · Allen County Commissioners policy (2025) (2025-11-04)
Allen County IN (Fort Wayne) adopted generative AI use policy: bars CJIS/PHI/PII in public LLMs, requires departmental approval, mandates human review of AI outputs, and prohibits AI-only adverse decisions in benefits or eligibility.
-
In effect
Rutherford County TN County AI Use Policy
Rutherford County, TN · Effective 2025-10-21 · Rutherford County Mayor policy (2025) (2025-10-21)
Rutherford County TN adopted AI use policy for county employees: bars PII/PHI/CJIS in public LLMs, requires departmental approval, and bans AI-only adverse decisions affecting residents.
-
In effect
Sonoma County CA AI Use Guidelines for County Government
Sonoma County, CA · Effective 2025-10-14 · Sonoma County Administrator policy (2025) (2025-10-14)
Sonoma County adopted AI use guidelines for county employees prohibiting PII/PHI in public LLMs, requiring departmental approval before AI use, mandating disclosure of AI assistance in resident-facing communications, and barring AI-only consequential decisions.
-
In effect
Lexington-Fayette Urban County Government AI Use Policy
Fayette County, KY · Effective 2025-09-23 · LFUCG Administrative Regulation on AI (2025) (2025-09-23)
Lexington-Fayette Urban County Government (consolidated city-county) adopted AI use policy: prohibits PII/PHI in public LLMs, requires CIO approval for AI procurement, mandates inventory, and requires impact review before deployment in resident-facing services.
-
In effect
Williamson County TN Generative AI Use Policy
Williamson County, TN · Effective 2025-09-09 · Williamson County Mayor policy (2025) (2025-09-09)
Williamson County TN (Franklin/Brentwood) adopted generative AI use policy: prohibits CJIS/PHI/PII in public LLMs, requires human review of AI outputs, and mandates departmental inventory of AI-enabled tools.
-
In effect
Lane County OR
Lane County, OR · Effective 2025-08-19 · Lane County Administrator policy (2025) (2025-08-19)
Lane County OR adopted generative AI use policy for county employees: prohibits PII/PHI/CJIS in public LLMs, requires departmental approval, mandates human review of AI outputs, and requires disclosure of AI assistance in resident-facing communications.
-
In effect
City of Indianapolis & Marion County IN Generative AI Use Policy
Marion County, IN · Effective 2025-07-22 · Indianapolis-Marion County Mayor / Administrator AI Policy (2025) (2025-07-22)
Indianapolis (Unigov) / Marion County adopted citywide and countywide generative AI use policy: prohibits PII/PHI/CJIS in public LLMs, requires CIO approval for AI procurement, mandates inventory, and requires impact review before AI-driven decisions in resident services.
-
In effect
Clackamas County OR Generative AI Use Policy
Clackamas County, OR · Effective 2025-07-01 · Clackamas County administrative order (2025) (2025-07-01)
Clackamas County issued a generative AI use policy for staff: prohibits CJIS, HIPAA, and PII entry into public LLMs; requires human-in-the-loop review; mandates departmental inventory of AI tools.
-
In effect
San Mateo County CA AI Use & Governance Policy
San Mateo County, CA · Effective 2025-06-10 · San Mateo County Manager policy (2025) (2025-06-10)
San Mateo County adopted AI use and governance policy: requires impact assessment before deployment of AI/ADS in resident-facing services, bans facial-recognition use by county departments without Board authorization, requires inventory of AI tools, and mandates annual public reporting.
-
In effect
Boulder County CO Generative AI Use Policy
Boulder County, CO · Effective 2025-05-13 · Boulder County Administrative Policy (2025) (2025-05-13)
Boulder County adopted generative AI use policy: requires staff training, prohibits entry of confidential or PII data into public LLMs, requires disclosure when AI is used in resident-facing communications, and bans AI-only decisions on benefits or enforcement.
-
In effect
Montgomery County MD AI Governance Framework
Montgomery County, MD · Effective 2025-04-30 · Montgomery County Executive Order 2-25 (AI) (2025-04-30)
Montgomery County Executive Order establishing AI governance framework: requires AI inventory, impact assessment before deployment in resident-facing services, mandatory human review of consequential decisions, prohibition on facial-recognition use by county departments without Council authorization, and annual public reporting.
-
In effect
FCPS formal generative AI restrictions — elementary ban, secondary authorization required
Fairfax County Public Schools, VA · Effective 2026-08-01 · Fairfax County Public Schools School Board formal policy action on generative AI restrictions (adopted July 16, 2026; effective SY 2026-27)
The Fairfax County School Board voted on July 16, 2026 to adopt formal generative AI restrictions that take effect for the 2026-27 school year. Elementary students are prohibited from using any generative AI tools. Secondary students may only use generative AI if they receive written authorization from a principal, superintendent, or designee for a specific project. Pre-K and kindergarten students are banned from using school-issued tablets and laptops, with exceptions for students whose IEP, 504 plan, or multilingual learner status requires device access. The restrictions supersede the district's prior interim guidance (FCPS Forward: AI & The Future of Learning, September 2025), which had approved certain tools including Adobe Express and a ChatGPT pilot for teachers. Parental opt-out for school-issued devices and a YouTube content firewall were also under consideration.
-
In effect
Board Policy O-AIU and CMS Generative AI Guidance (2025-26)
Charlotte-Mecklenburg Schools, NC · Effective 2025-10-28 · Board Policy O-AIU and CMS Generative AI Guidance (2025-26)
The Charlotte-Mecklenburg Schools board approved Board Policy O-AIU on Oct. 28, 2025, requiring an AI committee to review any AI system using staff or student data, mandating FERPA-compliant vetting, age-appropriate tools, and barring AI from replacing human decision-making.
-
In effect
MCSO AI-assisted body scanner deployment for jail contraband
Maricopa County, AZ (Maricopa County Sheriff's Office) · Effective 2025-10-20 · MCSO AI-assisted body scanner deployment for jail contraband detection (LINEV Systems)
The Maricopa County Sheriff's Office deployed ten AI-assisted X-ray body scanners across six jail facilities to detect internally concealed contraband on inmates using automated anomaly detection and drug-detection software.
-
In effect
Ordinance outlawing algorithmic rent price fixing in unincor
King County, WA · Effective 2025-09-23 · Ordinance outlawing algorithmic rent price fixing in unincorporated King County
King County (sponsored by Councilmember Teresa Mosqueda, passed Sept 23, 2025 as the 11th US jurisdiction) prohibits landlords in unincorporated King County from contracting with algorithmic rent-setting services like RealPage, letting harmed renters sue for up to $7,500 per violation plus damages and attorneys' fees.
-
In effect
District Policy 3750 - Artificial Intelligence (AI) Use
Washington County School District, UT · Effective 2025-09-08 · District Policy 3750 - Artificial Intelligence (AI) Use
Washington County (UT) School District's board policy frames AI as a teacher assistant requiring human oversight, generally prohibits using confidential or FERPA-protected student data with AI tools, and bars students from using AI to plagiarize, generate deepfakes, or bypass security filters.
-
In effect
Board directive to develop comprehensive AI use guidelines (
Miami-Dade County Public Schools, FL · Effective 2025-08-12 · Board directive to develop comprehensive AI use guidelines (tiered framework)
The Miami-Dade County Public Schools board approved a measure directing staff to create comprehensive ethical AI guidelines for students and teachers, including a tiered use framework and misuse-consequences, with recommendations due back to the board.
-
In effect
Johnson County Sheriff nationwide Flock ALPR search (abortio
Johnson County, TX (Johnson County Sheriff's Office) · Effective 2025-05-09 · Johnson County Sheriff nationwide Flock ALPR search (abortion 'death investigation')
Johnson County Sheriff's deputies ran nationwide Flock automated license plate reader searches across tens of thousands of cameras and thousands of networks to locate a woman in a self-managed-abortion investigation, illustrating an operational sheriff ALPR practice.
-
In effect
RTC of Southern Nevada Wide-Scale ZeroEyes AI Weapons-Detect
Regional Transportation Commission of Southern Nevada (RTC) · Effective 2024-06-19 · RTC of Southern Nevada Wide-Scale ZeroEyes AI Weapons-Detection Deployment
The RTC became the first US transit agency to deploy wide-scale ZeroEyes AI gun-detection analytics across its transit-center cameras, later expanding the program by over 300% to all eight transit centers.
-
In effect
Spokane County Real-Time Crime Center (RTCC) surveillance us
Spokane County, WA (Spokane County Sheriff's Office) · Effective 2023-04-01 · Spokane County Real-Time Crime Center (RTCC) surveillance use policy
The Spokane County Sheriff's RTCC fuses surveillance cameras, license plate readers, BriefCam video analytics, 911 and social media data for real-time intelligence while stating it does not use facial recognition biometric software and applies access controls and audits.
-
In effect
Central Bucks School District GoGuardian Beacon Student Moni
Central Bucks School District, PA · Effective 2023-03-01 · Central Bucks School District GoGuardian Beacon Student Monitoring Trial
Central Bucks SD (PA) authorized a district-wide trial of GoGuardian Beacon to conduct 24/7 AI monitoring of middle- and high-school students' online activity on district devices, with a potential $114,000+ subscription pending trial-data review.
-
In effect
Orange County SD Policy Manual, Policy 308 - Unmanned Aerial
Orange County, CA (Orange County Sheriff-Coroner Department) · Effective 2021-03-01 · Orange County SD Policy Manual, Policy 308 - Unmanned Aerial Vehicle (UAV)
The Orange County Sheriff's UAV policy sets rules for lawful, FAA Part 107-compliant drone operations, requiring mission briefs, after-action reports, and prohibiting missions that violate the public's privacy rights.
-
In effect
Suffolk County Jail AI inmate-call monitoring (LEO Technolog
Suffolk County, NY (Suffolk County Sheriff's Office) · Effective 2019-04-01 · Suffolk County Jail AI inmate-call monitoring (LEO Technologies 'Verus')
The Suffolk County Sheriff's jail deployed LEO Technologies' Verus AI, which uses Amazon speech-to-text to transcribe and keyword-flag inmate phone calls, monitoring over 2.5 million calls between April 2019 and May 2020.
-
In effect
PA Allegheny AFST
Allegheny County, PA · Effective 2016-08-01 · Allegheny County DHS AFST Methodology (May 2019 update)
Allegheny County deploys a predictive risk model — the Allegheny Family Screening Tool — to score child-welfare hotline calls. Decisions to screen-in cases for investigation incorporate AFST scores. The DOJ has investigated the tool for ADA discrimination concerns; the county continues to operate it with documented protocols.
-
Proposed / pending
Cook County Jail AI-powered video surveillance system (Brief
Cook County, IL (Cook County Sheriff / Cook County Jail) · Cook County Jail AI-powered video surveillance system (BriefCam) contract
The Cook County Sheriff's Office proposed a $1.12M three-year BriefCam contract to add AI video analytics, facial recognition, and object identification across Cook County Jail's video, drawing opposition from 80 community groups.
-
Proposed / pending
Policy Code 1910 Generative Artificial Intelligence (draft)
Wake County Public School System, NC · Policy Code 1910 Generative Artificial Intelligence (draft)
Wake County Public School System advanced draft Policy 1910 on generative AI on June 17, 2026, which discourages AI detectors, requires students to disclose and explain AI use and cite it, and bars sharing student PII with certain AI systems, pending board approval.
-
Proposed / pending
Fort Bend ISD GoGuardian Web Content Filter and Student Moni
Fort Bend Independent School District, TX · Fort Bend ISD GoGuardian Web Content Filter and Student Monitoring Procurement
Fort Bend ISD's board approved a procurement of GoGuardian web content filtering and monitoring modules not to exceed $1.6 million over five years, part of a wave of Houston-area districts (including Humble ISD and Cypress-Fairbanks ISD) deploying AI-driven student-device monitoring.
City / local automated decision-making rules (142)
-
In effect
NYC AEDT Bias Audit Law (LL 144)
New York City, NY · Effective 2023-01-01 · NYC Local Law 144 of 2021; NYC Admin. Code §§ 20-870 to 20-874
Employers and employment agencies in New York City may not use AI hiring or promotion tools unless the tool has passed an independent bias audit within the past year. Job candidates must be told an automated tool is being used and can request information about the data it relies on.
-
In effect
Oakland Surveillance Ordinance & FR Ban
Oakland, CA · Oakland, Cal., Mun. Code ch. 9.64
Oakland requires City Council approval and public use policies before city agencies acquire any surveillance technology, and bans city use of facial recognition. In December 2020 the city added first-in-the-nation bans on predictive policing and other biometric surveillance (such as voice and gait recognition). Remains in effect, overseen by Oakland's Privacy Advisory Commission.
-
Blocked / in litigation
Liu v. Willow Bridge/RealPage (Philadelphia)
Philadelphia, PA · Effective 2026-07-28 · Liu et al. v. Willow Bridge Property Co. & RealPage, Inc., Phila. County Ct. of Common Pleas (filed July 28, 2026)
Three class-action lawsuits were filed in Philadelphia's Court of Common Pleas on July 28, 2026 — the first known enforcement actions under Philadelphia's algorithmic rent-fixing ban (Bill 240823). Tenant Yiyao Liu and others sued Willow Bridge Property Co. (one of the largest U.S. residential property managers) and RealPage Inc., alleging Willow Bridge used RealPage's software to obtain rent recommendations derived from nonpublic competitor data in violation of the city ordinance. Plaintiffs seek treble damages or $2,000 statutory amount per violation, plus injunctive relief.
-
In effect
Berkeley CA "The Berkeley Rule" AI Policy (2026)
Berkeley, CA · Effective 2026-03-10 · City of Berkeley, "The Berkeley Rule" and AI Use Framework for City Government (City Council action March 10, 2026)
On March 10, 2026, the Berkeley City Council adopted "The Berkeley Rule" — a ten-principle framework authored by Councilmember Ben Bartlett to guide ethical, human-centered use of AI in all city operations. Companion AI guidelines from Councilmember Shoshana O'Keefe require departments to apply bias safeguards, maintain data privacy compliance, and ensure human oversight of automated decisions before deployment. The City Manager's office subsequently drafted a formal AI Administrative Regulation implementing these principles.
-
In effect
Portland OR GenAI Policy
Portland, OR · Effective 2026-03-06 · City of Portland, BTS GenAI Use Policy (2024)
City of Portland Bureau of Technology Services policy on generative AI use by city employees, with required disclosure and prohibitions on entering sensitive data.
-
In effect
Minneapolis algorithmic rent ban (Ord. 2025-010, eff. Mar 1, 2026)
Minneapolis, MN · Effective 2026-03-01 · Minneapolis Ord. 2025-010 (File 2024-01399), adding § 244.2070 to City Code, eff. March 1, 2026
Minneapolis City Council adopted Ordinance 2025-010 amending Title 12, Chapter 244 of the City Code to add Section 244.2070, prohibiting residential landlords from using algorithmic devices that employ nonpublic competitor data to recommend rental pricing or vacancy strategies. Effective March 1, 2026. A White House report estimated Twin Cities renters paid on average $324 more per unit annually due to pricing algorithms, with the national total exceeding $3.8 billion. Private right of action; license revocation possible for landlord violations.
-
In effect
NYC GUARD Act (Gov't AI Accountability)
New York City, NY · Effective 2025-12-26 · NYC Council Int. Nos. 199-A, 926-A, 1024-A (GUARD Act, passed Nov. 25, 2025; lapsed into law Dec. 26, 2025; Intro 1024-A = Local Law 195 of 2025)
The NYC City Council unanimously passed three bills on November 25, 2025 known as the GUARD Act (Guaranteeing Unbiased AI Regulation and Disclosure), creating independent oversight of city government AI use. The package creates an independent Office of Algorithmic Data Accountability, sets mandatory fairness-testing and transparency standards for all agency AI tools, and requires a public registry of every AI system that has undergone a pre-deployment assessment. Because Mayor Adams neither signed nor vetoed the bills within the 30-day window, they lapsed into law on December 26, 2025. Intro 1024-A was assigned Local Law 195 of 2025; the Local Law numbers for Intros 199-A and 926-A still await Legistar confirmation.
-
In effect
Seattle algorithmic rent-fixing ban (Ord. 127241 / SMC 7.34, July 2025)
Seattle, WA · Effective 2025-07-31 · Seattle Ord. 127241 / CB 121000, signed July 1, 2025, eff. July 31, 2025; codified SMC Chapter 7.34
Seattle City Council passed CB 121000 on June 24, 2025 (Mayor signed July 1, 2025; effective July 31, 2025), creating SMC Chapter 7.34 to prohibit algorithmic rent-fixing. The ordinance bans landlords from using software or data services that pool pricing recommendations based on nonpublic competitor data — targeting RealPage-style pricing coordination. Publicly available rent estimates and listings remain permitted. Penalties reach $7,500 per violation, and each affected rental unit counts separately. Tenants can also sue for actual damages plus attorneys' fees.
-
In effect
Hoboken Algorithmic Rent-Fixing Ban
Hoboken, NJ · Effective 2025-07-09 · Hoboken City Council ordinance banning algorithmic rent-fixing, adopted July 9, 2025
Hoboken, NJ banned landlords from using algorithmic rent-fixing software. The ordinance passed unanimously (8-0) on July 9, 2025 and took effect immediately. It defines 'price fixing using algorithmic pricing' as the use of software or algorithms that collect nonpublic competitor data to coordinate rental pricing across multiple properties. Violations carry fines up to $20,000 per offense, up to 90 days imprisonment, or up to 90 days of community service. All residential rental properties are covered, excluding medical/long-term care and detention facilities.
-
In effect
San Diego algorithmic rent price-fixing ban (Ord. O-21955, May 2025)
San Diego, CA · Effective 2025-06-12 · San Diego Ord. O-21955, adopted May 13, 2025, eff. June 12, 2025
San Diego City Council adopted Ordinance O-21955 on May 13, 2025 (effective June 12, 2025), prohibiting landlords from using algorithmic tools that rely on nonpublic competitor data — current lease rates, occupancy levels, and vacancy strategies from competing properties — to recommend residential rent prices. Public data tools and affordable-housing compliance software are permitted. Penalties reach $1,000 per violation per month per property. Tenants can sue for damages and recover attorney's fees. Before the ban, an estimated 22 percent of San Diego County landlords reported using tools such as RealPage.
-
In effect
Oakland GenAI Policy
Oakland, CA · Effective 2024-12-01 · City of Oakland ITD, Interim Security Guidelines for AI Usage (2024)
City of Oakland Information Technology Department policy on city employee use of generative AI tools, with disclosure rules and prohibitions on entering sensitive data.
-
In effect
Philadelphia Bill 240823 — Algorithmic Rent-Fixing Ban
Philadelphia, PA · Effective 2024-11-13 · Philadelphia Bill No. 240823 (adopted Oct. 24, 2024; signed Nov. 13, 2024; effective Nov. 13, 2024)
Philadelphia's Bill 240823 (sponsored by Councilmember Nicolas O'Rourke, passed 17-0 on October 24, 2024 and signed November 13, 2024) bars landlords from using revenue-management software that pools private competitor leasing data to coordinate rents, with fines up to $2,000 per violation and a private right of action for tenants. On July 28, 2026 three class-action lawsuits were filed — the first known enforcement actions under the ordinance — against Willow Bridge Property Co. and RealPage Inc.
-
In effect
Phoenix GenAI AUP
Phoenix, AZ · Effective 2024-03-01 · City of Phoenix, GenAI Acceptable Use Policy (2024)
City of Phoenix Information Technology Services Department policy on city employee use of generative AI tools, with disclosure rules and prohibitions on entering sensitive data.
-
In effect
DC AI Values Mayor's Order
Washington, DC · Effective 2024-02-08 · D.C. Mayor's Order 2024-028 (Feb. 8, 2024)
Mayor Bowser's order requires DC government agencies to check any AI deployment against six AI Values: clear benefit to the people, safety and equity, accountability, transparency, sustainability, and privacy and cybersecurity. It created an AI Taskforce, set deadlines including a mandatory AI procurement handbook, and requires every agency to submit an AI strategic plan in cohorts through October 2026.
-
In effect
San Jose AI Reviews Board
San Jose, CA · Effective 2023-08-01 · City of San Jose, AI Reviews Board (2023)
City of San Jose established an internal AI Reviews Board to review AI tools used by city departments and helped launch the multi-city GovAI Coalition for shared AI procurement standards.
-
In effect
Boston Interim GenAI Guidelines
Boston, MA · Effective 2023-05-18 · City of Boston, Interim Guidelines for Using Generative AI (May 18, 2023)
Boston Mayor's Office interim guidelines authorizing limited use of generative AI tools by city employees with required disclosure and prohibitions on entering sensitive data.
-
In effect
NYC EO 3 / Citywide AI Policy
New York City, NY · Effective 2022-01-19 · N.Y.C. Exec. Order No. 3 (Jan. 19, 2022)
Mayoral executive order consolidating NYC's technology agencies by redesignating the Department of Information Technology and Telecommunications as the Office of Technology and Innovation (OTI), which oversees the Mayor's Office of Data Analytics, the Chief Technology Officer, the Office of Information Privacy, NYC Cyber Command, NYC 311, and the Algorithms Management and Policy office.
-
In effect
NYC Algorithmic Tools Reporting (LL35)
New York City, NY · Effective 2022-01-15 · NYC Admin. Code § 3-119.5 (Local Law 35 of 2022)
Every NYC agency must publicly report, each year, every algorithmic tool it used to make or assist decisions that materially affect the public's rights, benefits, or access to services. Reports must describe each tool's purpose, the data it uses, and any vendor involvement, and are published as an open dataset.
-
In effect
Seattle Surveillance Ordinance
Seattle, WA · Effective 2017-09-01 · Seattle Ordinance 125376 (2017), SMC ch. 14.18, as amended 2018
Seattle requires city departments to get City Council approval before acquiring or using surveillance technologies, supported by public Surveillance Impact Reports and review by a community working group. One of the earliest and most comprehensive municipal surveillance-oversight laws in the country.
-
In effect
Cleveland OH Flock 6-month renewal w/ data-sharing restrictions (Jul. 15, 2026)
Cleveland, OH · Effective 2026-07-15 · Cleveland, OH City Council 9-6 vote, July 15, 2026, six-month Flock Safety renewal with no-data-sharing and no-fusion-center conditions
Cleveland City Council voted 9-6 on July 15, 2026 to keep the city's Flock Safety license plate reader cameras for another six months — but attached new restrictions the prior contract lacked. Under the renewal, Flock data may not be shared with other governments or third parties, and access by the regional fusion center is cut off. The short six-month term functions as a probationary period. This entry indexes a surveillance deployment renewal; the new data-sharing restrictions are the operative oversight conditions.
-
In effect
Huntington WV Flock contract approved 6-4 (Jul. 14, 2026)
Huntington, WV · Effective 2026-07-14 · Huntington, WV City Council 6-4 vote, July 14, 2026, approving $2.1M Flock Safety surveillance contract
The Huntington, West Virginia City Council voted 6-4 on July 14, 2026 to approve a $2.1 million contract with Flock Safety for a citywide surveillance package: 40 automated license plate readers, 17 cameras, 2 drones, 2 gunshot detectors, and audio detection capability. The vote came after a council meeting that ran more than 8 hours, at which more than 50 residents spoke in opposition. This entry indexes a government AI surveillance deployment, not a protection; available coverage describes no independent oversight, audit requirement, or data-sharing restrictions attached to the approval. Two days later the ACLU of West Virginia filed a mandamus petition challenging the contract (see litig-aclu-wv-v-huntington-flock-2026).
-
In effect
Fredericksburg VA Axon AI package w/ Draft One carve-out (Jul. 14, 2026)
Fredericksburg, VA · Effective 2026-07-14 · Fredericksburg, VA City Council authorization, July 14, 2026, of $1.9M/5-year Axon AI package (Draft One with critical-incident bar, translation, transcription, in-car cameras, mobile ALPR)
The Fredericksburg, Virginia City Council authorized a $1.9 million, five-year package with Axon on July 14, 2026 that adds AI capabilities across the police department: Draft One (Axon's generative AI police-report drafting tool), AI translation, transcription, in-car cameras, and mobile license plate readers. The package carries one notable guardrail: Draft One is optional for officers and is barred from use in critical incidents — meaning reports on the most serious events must be written by humans. Otherwise this entry indexes a government AI deployment.
-
In effect
Hillsborough County FL Public Schools Board Policy 2130
Tampa, FL · Effective 2026-06-02 · Hillsborough County FL Public Schools Board Policy 2130 — Emerging Technologies + AI Implementation Guide (2026-06-02)
Adopted Board Policy 2130 with an AI Implementation Guide; authorizes vetted AI primarily for teacher use, withholds student access to the enterprise platform initially, and is extending to AI smart-glasses restrictions in classrooms.
-
In effect
Austin Transparent and Responsible Use of Surveillance Techn
Austin, TX · Effective 2026-04-23 · Austin Transparent and Responsible Use of Surveillance Technology (TRUST) Act
After letting its Flock ALPR contract expire in 2025, the Austin City Council passed the TRUST Act requiring council approval and public review before departments can acquire, use, or share data from surveillance technology like license plate readers and drones.
-
In effect
Cambridge terminates Flock Safety ALPR contract for 'materia
Cambridge, MA · Effective 2025-12-09 · Cambridge terminates Flock Safety ALPR contract for 'material breach of trust'
After suspending its Flock cameras in October 2025 over fears data could reach ICE in violation of the city's sanctuary ordinance, Cambridge terminated the contract when Flock installed cameras without authorization.
-
In effect
Ordinance 192122 - Prohibition of anti-competitive algorithm
Portland, OR · Effective 2025-11-19 · Ordinance 192122 - Prohibition of anti-competitive algorithmic rental pricing (City Code 30.01.088)
Portland's Ordinance 192122 (passed 8-2 on Nov 19, 2025, effective ~Feb 2026) bans the sale and use of revenue-management 'algorithmic devices' that analyze competitor data to coordinate rents, with fines and a tenant right to sue up to $1,000 per violation.
-
In effect
Charlotte-Mecklenburg Schools
Charlotte, NC · Effective 2025-10-28 · Charlotte-Mecklenburg Schools — Board Policy on Artificial Intelligence (2025-10-28)
Eight-part board policy requiring cross-functional AI committee approval before any system using staff/student data is deployed. Mandates training, age-appropriate tools, public-records and regulatory compliance; AI cannot replace human decision-making.
-
In effect
Township High School District 211
Palatine, IL · Effective 2025-10-13 · Township High School District 211 — AI Use Guidelines (2025-10-13)
D211 guidelines authorize district-vetted enterprise AI tools, bar student entry of PII into non-approved AI, require teacher disclosure of AI use, and prohibit AI as sole basis for grading or discipline.
-
In effect
Greenwich CT Public Schools
Greenwich, CT · Effective 2025-09-25 · Greenwich CT Public Schools — Generative AI Use Guidelines (2025-09-25)
District-adopted guidelines: enterprise Microsoft Copilot and Google Gemini for Education for staff and grades 9-12; bar on consumer AI with student data; AI disclosure expectation; ban on AI as sole basis for grading or discipline.
-
In effect
Durham NC Public Schools
Durham, NC · Effective 2025-09-25 · Durham NC Public Schools — Generative AI Acceptable Use Guidelines (2025-09-25)
DPS Board-reviewed guidelines authorize district-vetted enterprise AI tools, require teacher disclosure of AI use in instruction, bar non-consensual deepfakes, prohibit AI-only grading or discipline, and require parental consent for student AI accounts under 13. Anchored in Policy 3225/4312/7320 (Technology Responsible Use).
-
In effect
Iowa City Community School District
Iowa City, IA · Effective 2025-09-25 · Iowa City Community School District — Generative AI Use Guidelines and Board Policy 605.8R1 (effective September 2025)
Iowa City Community School District (ICCSD) guidelines authorize Microsoft Copilot enterprise on district devices; bar student entry of PII into non-approved AI; require teacher disclosure of AI use; and prohibit AI as sole basis for grading or discipline. The district also adopted Board Policy 605.8R1 governing student use of technology including AI.
-
In effect
Prince William County VA Public Schools
Manassas, VA · Effective 2025-09-17 · Prince William County VA Public Schools — Generative AI Use Procedures (2025-09-17)
District-wide procedures authorize Microsoft Copilot for staff and grades 9-12; ban use of consumer AI with student data; AI disclosure expected on graded work; AI cannot make special-education or discipline decisions without human review.
-
In effect
Prince George's County MD Public Schools
Upper Marlboro, MD · Effective 2025-09-15 · Prince George's County MD Public Schools — Generative AI Use Procedure (2025-09-15)
Procedure approved alongside Board Policy 0123: limits enterprise AI access to approved systems only, bars input of student PII or confidential employee records into AI tools, requires professional accountability for AI-generated content, and may result in disciplinary action for policy violations. The procedure is AP 0123, not AP 0500.
-
In effect
Newton MA Public Schools
Newton, MA · Effective 2025-09-15 · Newton MA Public Schools — Generative AI Use Guidance (2025-09-15)
Newton Public Schools guidance covers vetted enterprise AI tools, classroom disclosure norms, prohibition on AI-generated discipline or special-education decisions, and AI literacy thread in grades 6-12.
-
In effect
Oakland Unified School District
Oakland, CA · Effective 2025-09-10 · Oakland Unified School District — AI Acceptable Use Guidelines (2025-09-10)
Board-approved guidelines: enterprise tool list, ban on AI tools that train on student inputs, AI disclosure on assignments, AI cannot be sole basis for academic placement or discipline.
-
In effect
Cleveland Metropolitan School District
Cleveland, OH · Effective 2025-09-09 · Cleveland Metropolitan School District — AI Acceptable Use Policy (2025-09-09)
Board-adopted AUP: vetted tool list, ban on uploading student records to generative models, AI literacy added to high-school graduation pathway, AI tool vendors must pass district privacy review.
-
In effect
Baltimore City Public Schools
Baltimore, MD · Effective 2025-09-09 · Baltimore City Public Schools — Generative AI Use Guidance (2025-09-09)
City Schools districtwide guidance authorizes vetted enterprise AI tools, bars student entry of PII into non-approved AI, requires teacher disclosure of AI use in instruction, and prohibits AI as sole basis for grading or discipline. Anchored in Board Policy IIBE (Acceptable Use).
-
In effect
Fresno USD AI Guidance
Fresno, CA · Effective 2025-09-09 · Fresno USD AI Guidance (2025-09-09)
Fresno Unified School District publishes official AI guidance on the district's IT/AI department page: district-vetted GenAI tools authorized, PII entry into non-approved AI barred, teacher disclosure when AI is used in instruction required, AI prohibited as the sole basis for grading or discipline.
-
In effect
AUHSD AI Guidance
Anaheim, CA · Effective 2025-09-03 · AUHSD AI Guidance (2025-09-03)
Anaheim Union High School District board adopted an AI policy on September 3, 2025: authorizes Microsoft Copilot enterprise and Khanmigo in closed-loop configurations, bars PII entry into non-approved AI, requires teacher disclosure of AI use, and prohibits AI-generated impersonation of students or staff.
-
In effect
NYC Public Schools Guidance on AI
New York, NY · Effective 2025-09-01 · NYC Public Schools Guidance on AI (2025-09-01)
NYC DOE districtwide guidance lists never-allowed uses, then conditional uses with safeguards. Staff barred from entering PII or sensitive info into GenAI tools not approved through ERMA review.
-
In effect
Fairfax County VA Public Schools
Fairfax, VA · Effective 2025-09-01 · Fairfax County VA Public Schools — FCPS Forward: AI & The Future of Learning (Interim) (2025-09-01)
Interim guidance while a board-adopted policy is drafted (Oct 2025). Approved tools include Adobe Express, Google Storybook/LM, ChatGPT for Teachers pilot configured not to train OpenAI models; students cannot be compelled to interact with AI.
-
In effect
School District of Philadelphia
Philadelphia, PA · Effective 2025-09-01 · School District of Philadelphia — Generative AI Guidelines (PASS program) (2025-09-01)
Approves Google Gemini and Adobe Express with Firefly in a 'walled garden' configuration so user data is not used to train external LLMs. Paired with a three-tier UPenn-developed PD program (PASS).
-
In effect
Boston Public Schools
Boston, MA · Effective 2025-09-01 · Boston Public Schools — Guidance on AI + Draft Districtwide Policy 2026 (2025-09-01)
Revised 2025 guidance plus a May 2026 draft policy that bans non-sanctioned AI use, non-consensual deepfakes, AI as sole basis for grading/discipline, and PII entry into unapproved tools. Moving toward AI literacy graduation requirement.
-
In effect
Volusia County FL Schools
DeLand, FL · Effective 2025-08-26 · Volusia County FL Schools — AI in the Classroom Guidelines (2025-08-26)
School Board Policy 428 and amendments to the Student Code of Conduct (Policy 208E/208S) govern AI use by Volusia County Schools staff and students. Students may use AI as a support tool for brainstorming, clarifying complex texts, or grammar assistance, but must cite AI assistance and may not submit AI-generated work as their own. Teachers may prohibit AI on specific assignments. The policy safeguards student data privacy and fosters equitable access; violations are handled under the district's existing disciplinary code.
-
In effect
Loudoun County VA Public Schools
Ashburn, VA · Effective 2025-08-26 · Loudoun County VA Public Schools — AI Use Guidelines (2025-08-26)
Largest NoVA-suburban district adopted guidelines: vetted enterprise AI tools, parental opt-in for student AI account creation grades 6-8, AI cannot be sole basis for placement or discipline, AI literacy integrated into K-12 ITRT curriculum.
-
In effect
Naperville Community Unit School District 203
Naperville, IL · Effective 2025-08-25 · Naperville Community Unit School District 203 — AI Use Guidance (2025-08-25)
Affluent Chicago suburban district adopted AI guidance: enterprise tools authorized, ban on student AI account creation under 13, AI disclosure expected on graded work, AI cannot be sole basis for placement or discipline.
-
In effect
Public Schools of Brookline
Brookline, MA · Effective 2025-08-19 · Public Schools of Brookline — AI Acceptable Use & Data Privacy Procedure (2025-08-19)
Town of Brookline municipal policy governing use of generative AI tools by all Town Technology Resources users. Distinguishes constrained (contractually approved, confidentiality guaranteed) from unconstrained (consumer, no guarantees) tools. Prohibits inputting PII or protected health information into any generative AI tool. Requires IT Cybersecurity Team approval before use of any generative AI tool. Adopted by the Select Board and also approved by the School Committee.
-
In effect
Mesa Public Schools AZ
Mesa, AZ · Effective 2025-08-19 · Mesa Public Schools AZ — Generative AI Use Guidelines (2025-08-19)
Mesa Public Schools (Arizona's largest district) adopted districtwide GenAI guidelines: authorizes Microsoft Copilot enterprise and Khanmigo for grades 9-12; requires teacher disclosure of AI use; bars student entry of PII into non-approved AI; and ties violations to Governing Board Policy IJNDB (Acceptable Use).
-
In effect
Houston ISD Generative AI Guidebook & Permission/Consent Form (SY 25-26)
Houston, TX · Effective 2025-08-01 · Houston ISD Generative AI Guidebook & Permission/Consent Form (SY 25-26) (2025-08-01)
Age-based GenAI access (Copilot for 14+), required parental consent forms, vetted product list, summer educator PD; allows teacher use for instructional and admin tasks.
-
In effect
Cherokee County GA School District
Canton, GA · Effective 2025-07-24 · Cherokee County GA School District — AI Use Procedure (2025-07-24)
Procedure approved with Board Policy IFBG update: enterprise AI authorized for staff and grades 9-12, no AI use for early-grade summative assessment, AI tools must be FERPA/COPPA compliant, AI use must be cited in graded work.
-
In effect
CTA ZeroEyes AI Gun-Detection Contract Expansion (250 to 1,5
Chicago Transit Authority (CTA) · Effective 2025-07-24 · CTA ZeroEyes AI Gun-Detection Contract Expansion (250 to 1,500 cameras)
The CTA board approved a $1.2M contract to expand ZeroEyes AI gun-detection software from 250 to 1,500 platform cameras by mid-2026, over civil-liberties objections about public input and effectiveness.
-
In effect
Santa Monica Algorithmic Rent-Setting Ban
Santa Monica, CA · Effective 2025-06-24 · Santa Monica City Council ordinance banning algorithmic rent-setting software, adopted approx. June 24, 2025
Santa Monica, CA banned the sale and use of algorithmic rent-setting software that relies on nonpublic competitor data to coordinate rental pricing. Adopted around June 24, 2025, the ordinance provides tenants with an affirmative defense in eviction proceedings where such software was used to set rent, and allows civil enforcement by renters or the city. The ordinance was motivated in part by housing affordability concerns following the January 2025 LA wildfires. It targets RealPage YieldStar-type systems that aggregate competitor pricing data to raise rents across multiple properties.
-
In effect
Dallas ISD AI Handbook (Policies DEC/EIA/FD/FNCA amended)
Dallas, TX · Effective 2025-06-24 · Dallas ISD AI Handbook (Policies DEC/EIA/FD/FNCA amended) (2025-06-24)
Board-adopted handbook for grades 9-12 requiring original student work, restricting access to 13+, requiring annual parental consent, addressing AI-enabled cyberbullying, and embedding AI equity as a 'new digital divide' priority.
-
In effect
Council Bill 121000 - Ban on algorithmic rent fixing (SMC 7.
Seattle, WA · Effective 2025-06-24 · Council Bill 121000 - Ban on algorithmic rent fixing (SMC 7.34)
Seattle's CB 121000 (sponsored by Councilmember Cathy Moore, passed 7-0 on June 24, 2025, signed July 1, 2025) prohibits landlords from using software that runs automated analysis of housing-market data to generate inflated rent recommendations, with penalties up to $7,500 per violation and a tenant private right of action.
-
In effect
Lee's Summit MO
Lees Summit, MO · Effective 2025-06-17 · Lee's Summit MO — Generative AI Use Resolution (2025-06-17)
Council resolution establishes citywide AI use principles: human review, bar on PII entry into consumer AI, IT/legal vetting before procurement, and disclosure of AI assistance in resident-facing communications.
-
In effect
Ordinance prohibiting price-fixing rental algorithms
Providence, RI · Effective 2025-05-15 · Ordinance prohibiting price-fixing rental algorithms
Providence (ordinance by Council President Rachel Miller, final passage May 15, 2025) bans landlords from using price-fixing rental algorithms like RealPage, with civil penalties up to $500 per day per instance of violation.
-
In effect
Ordinance banning algorithmic rent-setting software
Jersey City, NJ · Effective 2025-05-14 · Ordinance banning algorithmic rent-setting software
Jersey City passed a ban on algorithmic rent-setting software in May 2025 after statewide New Jersey efforts stalled, prohibiting landlords from using coordinated pricing algorithms.
-
In effect
Culver City CA
Culver City, CA · Effective 2025-04-28 · Culver City CA — Generative AI Use Policy for City Staff (2025-04-28)
Council-adopted staff policy: enterprise Microsoft Copilot only; bar on entry of confidential/PII data into consumer AI; disclosure of AI assistance in public communications; review by IT/HR before deploying AI in personnel decisions.
-
In effect
Austin AI Governance Resolution (2025)
Austin, TX · Effective 2025-04-24 · City of Austin, Tex., Resolution 20250424-055 (adopted Apr. 24, 2025)
The Austin City Council voted unanimously on April 24, 2025 to adopt Resolution 20250424-055, establishing an ethical AI governance framework for municipal operations. The resolution prohibits real-time employee surveillance by AI, bans AI-based productivity scoring or behavioral monitoring without human supervisor review and verification, bars AI from automated policing decisions, and creates a 'no displacement without consultation' labor policy guaranteeing that no AI system will significantly alter or eliminate job classifications without prior notice and consultation with affected employees and their unions. It also requires an annual public audit of all city AI use, mandates human review and oversight for all AI-influenced decisions, and directs the City Manager to study the environmental and equity impacts of data centers in the region. Sponsored by Mayor Pro Tem Vanessa Fuentes.
-
In effect
Denver Public Schools AI Handbook
Denver, CO · Effective 2025-04-01 · Denver Public Schools AI Handbook (2025-04-01)
Effective April 2025, DPS authorized MagicSchool, Gemini, and NotebookLM on district devices with output monitoring and data safeguards; 1,200 teachers trained; launching a student AI advisory council.
-
Proposed / pending
Ordinance prohibiting use of algorithmic rent-setting device
Berkeley, CA · Effective 2025-03-11 · Ordinance prohibiting use of algorithmic rent-setting devices (Berkeley City Council, March 11, 2025; suspended 2025 pending RealPage litigation)
Berkeley's City Council voted 8-1 in March 2025 to prohibit landlords from using algorithms to coordinate rent prices or manage vacancies. The ban was subsequently suspended by a follow-up Council ordinance after RealPage filed a First Amendment lawsuit challenging the measure. The suspension ordinance's second reading was scheduled for July 8, 2025; a November 2025 amendment extended the suspension to March 1, 2026. Post-March 2026 status remains unclear — RealPage litigation is ongoing. The ban is currently NOT being enforced.
-
In effect
Howard County MD Public School System
Ellicott City, MD · Effective 2025-03-03 · Howard County MD Public School System — AI Use Policy Statement & Policy 8080 Update (2025-03-03)
Board approved (January 30, 2025, effective March 3, 2025) modifications to Policy 8080 — Responsible Use of Technology, Digital Tools, and Social Media — restricting student personal device (cell phone) use during the school day for all PreK-12 students, with limited exceptions for documented IEP/504/health needs. The policy does not contain an explicit AI section; AI use is addressed only implicitly through broad digital-tools and academic-integrity language.
-
In effect
Olathe KS
Olathe, KS · Effective 2025-02-18 · Olathe KS — Generative AI Acceptable Use Policy (Council Adoption) (2025-02-18)
Council-adopted citywide AI acceptable use policy: bar on entry of confidential/PII data into consumer AI, required disclosure of AI assistance in public communications, IT review for any new AI procurement, and prohibition on AI as sole basis for personnel decisions.
-
In effect
Seattle Public Schools AI Handbook + Superintendent Procedure 2022SP
Seattle, WA · Effective 2025-02-01 · Seattle Public Schools AI Handbook + Superintendent Procedure 2022SP (2025-02-01)
Handbook operates alongside SP 2022SP (Electronic Resources). Requires approved tools to comply with privacy law, treats unauthorized AI use or uncited use as a disciplinary policy breach, and directs schools to teach AI citation.
-
In effect
San Diego Unified School District
San Diego, CA · Effective 2024-12-10 · San Diego Unified School District — Generative AI Use Guidelines (2024-12-10)
District guidelines: enterprise AI authorized for staff and grades 9-12, bar on consumer AI for student-data tasks, AI disclosure expectations, AI literacy integrated into K-12 educational technology standards.
-
In effect
Overland Park KS
Overland Park, KS · Effective 2024-12-02 · Overland Park KS — AI Acceptable Use Policy (2024-12-02)
Council adoption of citywide AI use policy with vetted-tool list, ban on PII entry into public AI, disclosure for AI-assisted public communications, and mandatory training before staff AI use.
-
In effect
Frederick MD
Frederick, MD · Effective 2024-11-21 · Frederick MD — City Generative AI Use Policy (2024-11-21)
Mayor & Board of Aldermen adoption: citywide AI policy with vetted-tool list, bar on PII entry into consumer AI, disclosure expectations for AI-assisted public communications, and IT review of AI procurement.
-
In effect
Broward County FL Powered by AI
Fort Lauderdale, FL · Effective 2024-11-15 · Broward County FL Powered by AI — Responsible Use Framework (2024-11-15)
Task force framework mandating human oversight, supporting the largest K-12 Microsoft Copilot deployment, requiring a school AI liaison at each campus, and pairing with student literacy and educator training.
-
In effect
San Francisco Unified School District
San Francisco, CA · Effective 2024-11-12 · San Francisco Unified School District — Generative AI Use Guidelines (2024-11-12)
District guidelines authorize Microsoft Copilot enterprise for staff; bar student AI accounts under 13; require teacher disclosure when AI is used for instructional design; bar AI use to make discipline or placement decisions without human review.
-
In effect
Arlington VA Public Schools
Arlington, VA · Effective 2024-10-24 · Arlington VA Public Schools — Guidance on AI Use in APS (2024-10-24)
Districtwide guidance authorizes vetted enterprise tools (Microsoft Copilot, Google Gemini for Education), bars student PII entry into consumer AI, requires teacher disclosure to families when AI is used in instructional design, and prohibits AI as sole basis for grading or discipline.
-
In effect
Princeton NJ Public Schools
Princeton, NJ · Effective 2024-10-22 · Princeton NJ Public Schools — AI Use Guidelines (2024-10-22)
District guidelines: vetted enterprise AI list, prohibition on student AI chatbot use grades K-5, AI disclosure expectation on graded work, ban on AI as sole basis for academic placement decisions.
-
In effect
Ordinance prohibiting sale or use of algorithmic devices to
San Francisco, CA · Effective 2024-10-14 · Ordinance prohibiting sale or use of algorithmic devices to set rents (Administrative Code / Rent Ordinance Section 37.10C)
San Francisco, the first US city to do so, bans landlords from selling or using algorithmic revenue-management software that uses non-public competitor data to recommend rents or occupancy levels, with civil penalties up to $1,000 per violation plus damages and attorneys' fees.
-
In effect
Santa Clara County CA Office of Education
San Jose, CA · Effective 2024-10-10 · Santa Clara County CA Office of Education — AI Guidance for Member Districts (2024-10-10)
County-office guidance to 31 member districts: AI tool vetting framework, model staff/student use policies, data-privacy addendum template for AI vendors, and shared educator PD on responsible AI use.
-
In effect
Saint Paul Public Schools
Saint Paul, MN · Effective 2024-10-08 · Saint Paul Public Schools — Generative AI Acceptable Use Guidance (2024-10-08)
Guidance designates Google Gemini, NotebookLM, Seesaw, and Schoology PowerBuddy as approved AI tools for staff (offered through district accounts with enterprise protections), bars use of consumer AI tools with student data, requires teacher disclosure to families when AI is used for instructional design, and prohibits AI-generated discipline recommendations without administrator review.
-
In effect
Real-Time Crime Center Surveillance Impact Report and Crime
Seattle, WA · Effective 2024-10-01 · Real-Time Crime Center Surveillance Impact Report and Crime Prevention Technology Pilot legislation
Seattle's Real-Time Crime Center was authorized under the city's surveillance ordinance through a Council-approved Surveillance Impact Report, requiring Council sign-off for material changes and an independent Office of Inspector General evaluation of its analytics.
-
In effect
Olympia WA
Olympia, WA · Effective 2024-09-24 · Olympia WA — Artificial Intelligence Use Policy (2024-09-24)
Council-approved AI use policy: enterprise Microsoft Copilot for staff; bar on consumer AI with city data; disclosure on public-facing AI-assisted materials; IT vetting for new AI tools.
-
In effect
Glendale CA
Glendale, CA · Effective 2024-09-17 · Glendale CA — Generative AI Use Policy (City Manager Directive) (2024-09-17)
City Manager directive adopted via Council action: requires departments to use only city-approved AI tools, disclose AI assistance in public communications, and route AI procurement through IT review. Surfaced through Glendale's PrimeGov agenda packet.
-
In effect
Forsyth County GA Schools
Cumming, GA · Effective 2024-09-12 · Forsyth County GA Schools — Generative AI Use Guidelines (Forsyth.AI initiative) (2024-09-12)
District 'Forsyth.AI' initiative pairs adopted use guidelines with a custom secure AI portal for staff and grades 6-12; bars PII entry into external models, requires teacher verification of AI output, and prohibits AI use to make student-discipline or special-education decisions.
-
In effect
Minneapolis Public Schools
Minneapolis, MN · Effective 2024-09-04 · Minneapolis Public Schools — AI Guidance for Educators (2024-09-04)
District-issued educator guidance: vetted tool list, ban on entering student IEP or behavior data into generative AI, AI must not be sole basis for academic placement or discipline, recommended classroom disclosure when AI is used to create materials.
-
In effect
Dallas GenAI Directive
Dallas, TX · Effective 2024-09-01 · City of Dallas Admin. Directive, Generative AI Use (2024)
City of Dallas administrative directive on generative AI use by employees, with disclosure, prohibited data, and review requirements.
-
In effect
Hartford GenAI Policy
Hartford, CT · Effective 2024-09-01 · City of Hartford MHIS, GenAI Acceptable Use Policy (2024)
City of Hartford administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Greensboro GenAI Policy
Greensboro, NC · Effective 2024-09-01 · City of Greensboro IT Dept., GenAI Acceptable Use Policy (2024)
City of Greensboro administrative policy on employee use of generative AI tools with disclosure, prohibited-data, and human-review requirements.
-
In effect
OKC GenAI Policy
Oklahoma City, OK · Effective 2024-09-01 · City of OKC IT Dept., GenAI Acceptable Use Policy (2024)
City of Oklahoma City administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Salem OR GenAI Policy
Salem, OR · Effective 2024-09-01 · City of Salem OR IT Dept., GenAI Acceptable Use Policy (2024)
City of Salem OR administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Hialeah GenAI Policy
Hialeah, FL · Effective 2024-09-01 · City of Hialeah, Resolution No. 2024-346 (2024)
City of Hialeah administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Montgomery County MD Public Schools
Rockville, MD · Effective 2024-08-29 · Montgomery County MD Public Schools — Guidelines for Use of Artificial Intelligence (2024-08-29)
MCPS issued districtwide AI guidelines authorizing teacher use of vetted tools (Google Gemini for Education, Microsoft Copilot), barring student entry of personal data into GenAI, requiring teacher disclosure when AI generates student feedback, and prohibiting AI-only disciplinary or grading decisions. Implemented via Board Policy IGS (Educational Technology) administered through BoardDocs.
-
In effect
Policy 5110 - CCSD Policy on Generative Artificial Intellige
Chappaqua Central School District, NY · Effective 2024-08-29 · Policy 5110 - CCSD Policy on Generative Artificial Intelligence (AI) Integration
Chappaqua CSD's board-adopted GenAI policy prohibits district users from inputting FERPA-protected student data or Education Law 2-d protected information into AI systems, requires use of only Ed Law 2-d compliant approved tools with students, and mandates transparency about how AI is used.
-
In effect
Jefferson County CO Public Schools (Jeffco)
Golden, CO · Effective 2024-08-22 · Jefferson County CO Public Schools (Jeffco) — Guidelines for the Use of Generative AI (2024-08-22)
Districtwide guidelines: enterprise tools (Google Gemini for Education, Microsoft Copilot) authorized; bar on staff entering student data into consumer AI products; AI disclosure expectations for instructional materials; required AI literacy PD for staff.
-
In effect
Miami-Dade County Public Schools
Miami, FL · Effective 2024-08-15 · Miami-Dade County Public Schools — Generative AI Use and District Guidance (2024-08-15)
M-DCPS, the nation's third-largest district, adopted districtwide GenAI guidance directing approved tools (Google Gemini for Education, Microsoft Copilot enterprise), barring entry of student PII into non-approved models, and requiring teacher review of any AI-generated student-facing materials. Paired with M-DCPS Board Policy 7540.03 (Student Use of Technology) administered through BoardDocs.
-
In effect
Clark County NV STELLAR AI Framework
Las Vegas, NV · Effective 2024-08-15 · Clark County NV STELLAR AI Framework — District Implementation (2024-08-15)
Implements Nevada's STELLAR framework with a district safe list and closed-loop systems that prevent student data from training external models; ties to school-level academic integrity policies.
-
In effect
Chicago Public Schools AI Guidebook
Chicago, IL · Effective 2024-08-01 · Chicago Public Schools AI Guidebook — Guidance for Generative AI Use (2024-08-01)
Quarterly-updated CPS guidance permits district-approved tools with teacher permission; bars PII/PHI/confidential data entry. Warns against AI-detection software due to false-positive risk for English learners.
-
In effect
KCMO GenAI Policy
Kansas City, MO · Effective 2024-08-01 · City of Kansas City MO, GenAI Use Policy (2024)
City of Kansas City Missouri administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review requirements.
-
In effect
Providence GenAI Policy
Providence, RI · Effective 2024-08-01 · City of Providence IT Dept., GenAI Acceptable Use Policy (2024)
City of Providence administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Tulsa GenAI Policy
Tulsa, OK · Effective 2024-08-01 · City of Tulsa IT Dept., AI Policy No. 1300-COP-AI-POLICY (eff. Feb. 25, 2026)
City of Tulsa administrative policy on employee use of generative AI tools, with disclosure, prohibited-data, and human-review rules.
-
In effect
Birmingham AL GenAI Policy
Birmingham, AL · Effective 2024-08-01 · City of Birmingham AL, Interim Guidelines For Using Generative Artificial Intelligence (2024)
City of Birmingham AL administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Henderson NV GenAI Policy
Henderson, NV · Effective 2024-08-01 · City of Henderson NV IT Dept., GenAI Acceptable Use Policy (2024)
City of Henderson NV administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Vancouver Public Schools Gaggle Safety Management Student Mo
Vancouver Public Schools, WA · Effective 2024-08-01 · Vancouver Public Schools Gaggle Safety Management Student Monitoring Contract
Vancouver Public Schools (WA) signed a $328,036 three-year Gaggle Safety Management contract to run AI monitoring of 24,000+ students' typing on district devices at school and at home to flag violence, self-harm, and safety concerns.
-
In effect
Gwinnett County GA Public Schools
Lawrenceville, GA · Effective 2024-07-15 · Gwinnett County GA Public Schools — Guidance for Human-Centered AI Use (2024-07-15)
Requires critical review of AI-generated content and humans in the loop; prohibits privacy-compromising uses. Paired with the GCPS AI-Ready Framework developed with Google, Microsoft, and higher-ed partners.
-
In effect
Long Beach CA
Long Beach, CA · Effective 2024-07-09 · Long Beach CA — Generative AI Guidance (Administrative Guidance, not a formal Council Acceptable Use Policy) (2024-07-09)
The City of Long Beach published a Generative AI Interim Guidance (now at version 1.3) as an administrative tool to help staff use generative AI safely and responsibly — covering risks around AI bias, data privacy, and cybersecurity. The guidance explicitly states it is not a policy or ordinance. The Legistar council-file URL in the original entry could not be confirmed via official search results.
-
In effect
San Diego GenAI Policy
San Diego, CA · Effective 2024-07-01 · City of San Diego Admin. Reg., Generative AI Use (2024)
San Diego administrative policy governing employee use of generative AI tools, with disclosure, data-handling, and prohibited-use rules.
-
In effect
Metro Nashville GenAI Policy
Nashville, TN · Effective 2024-07-01 · Metro Nashville ITS, ISM-20: Artificial Intelligence and Generative Artificial Intelligence Use (Aug 2025)
Metropolitan Government of Nashville and Davidson County administrative policy on generative AI tool use by employees, with disclosure and data-handling rules.
-
In effect
Reno GenAI Policy
Reno, NV · Effective 2024-07-01 · City of Reno IT Dept., GenAI Acceptable Use Policy (2024)
City of Reno administrative policy on employee use of generative AI tools with disclosure, prohibited-data, and human-review rules.
-
In effect
Wilmington DE GenAI Policy
Wilmington, DE · Effective 2024-07-01 · City of Wilmington DE IT Dept., GenAI Acceptable Use Policy (2024)
City of Wilmington DE administrative policy on employee use of generative AI with disclosure, prohibited-data, and human-review rules.
-
In effect
Arlington TX GenAI Policy
Arlington, TX · Effective 2024-07-01 · City of Arlington TX City Manager's Office / Strategic Initiatives, Generative AI Security Policy (approved 11/18/2024)
City of Arlington TX administrative policy on employee use of generative AI tools with disclosure, prohibited data, and human-review rules.
-
In effect
Plano GenAI Policy
Plano, TX · Effective 2024-06-01 · City of Plano, Generative AI Employee Use Policy (2024)
City of Plano administrative policy on employee use of generative AI tools, with disclosure, data-handling, and human-review rules.
-
In effect
Louisville Metro GenAI Policy
Louisville, KY · Effective 2024-06-01 · Louisville Metro Office of Technology, GenAI Use Policy (2024)
Louisville Metro administrative policy on employee use of generative AI tools, with prohibited data and disclosure rules.
-
In effect
SLC GenAI Policy
Salt Lake City, UT · Effective 2024-06-01 · Salt Lake City IMS, GenAI Acceptable Use Policy (2024)
Salt Lake City Information Management Services administrative policy on employee use of generative AI tools with disclosure and prohibited-data rules.
-
In effect
St. Louis GenAI Policy
St. Louis, MO · Effective 2024-06-01 · City of St. Louis ITSA, Guidance on Generative AI (Oct. 2023)
City of St. Louis administrative policy on employee use of generative AI tools, with disclosure, data, and human-review rules.
-
In effect
Fort Worth GenAI Policy
Fort Worth, TX · Effective 2024-05-01 · City of Fort Worth, Generative Artificial Intelligence (AI) Policy (approved Dec. 18, 2023)
Fort Worth administrative policy governing employee use of generative AI, with mandatory disclosure, prohibited data categories, and human review requirements.
-
In effect
LAUSD BUL-151113.0
Los Angeles, CA · Effective 2024-04-08 · LAUSD BUL-151113.0 — Guidelines for Authorized Use of AI (2024-04-08)
LAUSD authorized-use guidelines for employees, students, and associated persons. Works with BUL-999.15; requires district-approved tools, bars confidential/PII entry into non-approved GenAI, and mandates educator review of AI outputs.
-
In effect
San Antonio GenAI Pilot Governance
San Antonio, TX · Effective 2024-04-01 · City of San Antonio ITSD, Administrative Directive 7.4a Attachment A – Acceptable Use of Generative AI Tools (May 2024); CIO Position Statement on AI Standards for COSA (January 2024)
San Antonio Information Technology Services Department governs generative AI through two instruments: a January 2024 CIO Position Statement providing an AI risk framework and playbook for all city employees, and a May 2024 Attachment A to Administrative Directive 7.4a titled 'Acceptable Use of Generative AI Tools' covering responsible use of third-party GenAI tools. AI technologies are tested and validated before procurement via AI FactSheet, Risk Assessment, and Findings Report. The 'SmartSA' branding in the original entry is inaccurate — these are ITSD administrative instruments, not SmartSA program documents.
-
In effect
Seattle Generative AI Policy
Seattle, WA · Effective 2023-11-01 · City of Seattle, GenAI Policy POL-209 (eff. Nov. 1, 2023)
Seattle's generative AI policy governs how city employees use tools like ChatGPT. It requires attribution of AI-generated work, human review of all AI output before release, and limits on feeding personal information into AI systems, built around seven principles including bias reduction, transparency, and explainability.
-
In effect
San Jose GenAI Guidelines
San Jose, CA · Effective 2023-07-25 · City of San Jose, Generative AI Guidelines (June 12, 2023)
San Jose published one of the first US city-government playbooks for generative AI, requiring staff to log every use of tools like ChatGPT, complete training, and refrain from entering confidential information.
-
In effect
Peninsula School District AI Guidance (Principles and Belief
Peninsula School District, WA · Effective 2023-07-15 · Peninsula School District AI Guidance (Principles and Beliefs for AI Use)
One of the first US districts to publish AI guidance, Peninsula SD (WA) sets principles requiring staff to be diligent custodians of student data, cautions against unreliable AI detection tools, and mandates transparency and human oversight in all AI use.
-
In effect
Surveillance Technology and Data Protection ordinance bannin
New Orleans, LA · Effective 2020-12-17 · Surveillance Technology and Data Protection ordinance banning NOPD facial recognition and predictive policing
New Orleans' City Council banned NOPD use of facial recognition, stingrays, and predictive policing in 2020, but the council rolled back the facial recognition ban to permit limited use in 2022.
-
In effect
Oakland City Council Drone Use Policy plus expanded biometri
Oakland, CA · Effective 2020-12-16 · Oakland City Council Drone Use Policy plus expanded biometric-surveillance and predictive-policing bans (amended Surveillance Transparency Ordinance)
On December 16, 2020, the Oakland City Council approved a drone use policy requiring annual reporting and, via revisions to its surveillance transparency ordinance, expanded its facial-recognition ban to other biometric surveillance and barred predictive-policing software.
-
In effect
Amendments to the Surveillance and Community Safety (CCOPS)
Oakland, CA · Effective 2020-12-15 · Amendments to the Surveillance and Community Safety (CCOPS) Ordinance prohibiting predictive policing analytics
Oakland amended its Community Control of Police Surveillance ordinance to expressly prohibit city use of predictive policing analytics (and biometric surveillance) while requiring City Council approval, with resident input, for any other surveillance technology.
-
In effect
Ordinance requiring City Council approval before police use
Pittsburgh, PA · Effective 2020-09-22 · Ordinance requiring City Council approval before police use of facial recognition and predictive policing technology
Pittsburgh's City Council barred the police bureau from obtaining or using facial recognition or predictive policing technology without prior City Council approval, functioning as a moratorium on new use.
-
In effect
Ordinance banning municipal use of predictive policing and f
Santa Cruz, CA · Effective 2020-06-23 · Ordinance banning municipal use of predictive policing and facial recognition technology
Santa Cruz became the first U.S. city to bar its police department from using predictive policing (and facial recognition) technology unless the City Council finds by resolution that it is peer-reviewed, unbiased, and protective of civil rights.
-
Proposed / pending
Bellingham Initiative 26-01 to Ban Algorithmic Rental Price-
Bellingham · Bellingham Initiative 26-01 to Ban Algorithmic Rental Price-Fixing
A certified citizen initiative would prohibit landlords from using algorithmic coordinating services to set rental prices, heading toward Bellingham's November 2026 ballot.
-
In effect
NYC AI Action Plan
New York City, NY · NYC OTI, AI Action Plan (Oct. 2023)
NYC's AI Action Plan is the city's roadmap for responsible government AI use, with 37 action items covering AI principles, agency guidance, procurement standards, risk assessment, and public engagement. It is policy guidance from the mayor's Office of Technology and Innovation rather than binding law; annual progress reports have followed.
-
In effect
San José AI Policy
San Jose, CA · City of San José Policy Manual § 1.7.12; GenAI Guidelines (2023, as updated)
San José adopted a citywide AI policy and generative AI guidelines governing how city staff use AI tools. Employees must register AI uses with the city's Privacy and AI team, may not let AI make actionable decisions about residents (like approving applications), and must review AI outputs. San José also founded the GovAI Coalition, whose AI policy templates have been adopted by 100+ public agencies.
-
In effect
Long Beach GenAI Guidance
Long Beach, CA · City of Long Beach, GenAI Guidance v1.3; AI Strategy (2025)
Long Beach's Smart City program issued Generative AI Guidance (now v1.3) for city staff, covering AI bias, data privacy, and cybersecurity, and in 2025 published a citywide AI Strategy committing to an AI use-case registry, workforce training, and community engagement. It builds on the city's council-approved 2021 Data Privacy Guidelines.
-
In effect
Pittsburgh GenAI Use Policy
Pittsburgh, PA · City of Pittsburgh internal GenAI policy (2023, updated 2024)
Pittsburgh adopted an internal policy on generative AI use by city staff, informed by the University of Pittsburgh's Task Force on Public Algorithms. It bars staff from entering private city data into tools like ChatGPT, prohibits AI use in applications that affect residents' rights or safety, forbids relying on generative AI for decisions, and requires AI use to be disclosed and logged.
-
In effect
Wake County NC Public School System
Raleigh, NC · Wake County NC Public School System — Generative AI Guidelines & Policy 6446 Revision (undefined)
Board-revised Policy 6446 (Internet/Online Services) plus standalone AI guidelines: district-approved AI tools list, K-5 prohibition on student-facing AI chatbots, required parental consent for student AI accounts grades 6-8, AI literacy requirement for grades 9-12.
-
Proposed / pending
Use of Algorithms in Rental Rates Ordinance
Minneapolis, MN · Use of Algorithms in Rental Rates Ordinance
Minneapolis (third US city, 11-2 vote in March 2025) prohibits owners from using 'algorithmic devices' relying on non-public competitor data to set rents or occupancy, enforced through rental-license self-attestation and a tenant private right of action, effective March 1, 2026.
-
Expired
Denver ends Flock Safety ALPR contract and replaces vendor a
Denver, CO · Denver ends Flock Safety ALPR contract and replaces vendor amid data-sharing concerns
After Denver ended its Flock contract over privacy and federal data-sharing concerns, the City Council voted on March 31, 2026 to approve a smaller replacement ALPR contract with Axon, with several members demanding an ALPR-regulating ordinance first.
-
Proposed / pending
Guidance on Artificial Intelligence (preliminary 'traffic li
New York City Public Schools, NY · Guidance on Artificial Intelligence (preliminary 'traffic light' framework)
NYC Public Schools issued preliminary AI guidance using a green/yellow/red 'traffic light' framework that permits some staff and student uses, requires human review for others, and prohibits AI in grading, discipline, IEPs and placement decisions, with a fuller playbook to follow.
-
Proposed / pending
Cambridge MA algorithmic rent-setting ban (policy order, Jun. 2026)
Cambridge, MA · Cambridge, MA City Council unanimous policy order (late June 2026) directing draft ordinance banning algorithmic rent-setting (Councillor Sobrinho-Wheeler)
The Cambridge, Massachusetts City Council voted unanimously in late June 2026 on a policy order directing city staff to draft an ordinance banning algorithmic rent-setting — software (such as RealPage-style tools) that landlords use to coordinate and set rents. The order, led by Councillor Sobrinho-Wheeler, follows municipal bans in Berkeley, CA and Providence, RI. A policy order directs drafting; the ban itself is not yet law, so this is indexed as proposed until an ordinance is drafted and enacted.
-
Proposed / pending
Office of Artificial Intelligence Oversight
New York City · NYC Int 0919-2026
Would establish an Office of Artificial Intelligence Oversight within the Department of Consumer and Worker Protection. The office would investigate complaints about AI systems violating consumer protection laws, recommend enforcement actions, maintain a public complaint portal, run AI-harm consumer awareness campaigns, and propose rules clarifying how existing consumer protections apply to AI.
-
Proposed / pending
AI Gendered Impact Assessment + Interagency Taskforce
New York City · NYC Int 0287-2026
Requires the Department of Information Technology and Telecommunications to conduct biennial assessments of whether algorithmic tools using gender data may create disparate impacts. Establishes an interagency task force meeting at least twice yearly to evaluate how AI affects city employees' employment outcomes by gender (job displacement, role changes). Task force draws from administrative services, worker protection, human rights, technology, and gender equity agencies.
-
Status unknown
NYC resolution urging NY State to pass Advanced AI Licensing Act (A.3356)
New York City · NYC Res 0175-2026
Resolution urging the NY State Legislature to enact, and Governor Hochul to sign, the Advanced AI Licensing Act (A.3356) — which would establish state oversight through the Department of State, require licensing for high-risk AI systems, and ban particularly dangerous applications like autonomous weapons.
-
Status unknown
Atlanta City Council resolution accepting AI Commission recommendations
Atlanta · Atlanta 26-R-3663 (introduced June 1, 2026)
Resolution accepting the final report and 16 recommendations of the Atlanta AI Commission. Recommendations include equity impact assessments in AI procurement, role-specific staff training, cybersecurity standards for AI vendors, a public registry of all AI systems in use across City departments, and creation of a permanent AI Advisory Board co-chaired by the City's Chief Information Officer and Senior Technology Advisor. Directs the Mayor's office to examine administrative implementation steps while Council considers legislative follow-up.
-
Proposed / pending
DC SDAA (B24-0558)
Washington, DC · B24-0558 (DC Council, 2021; reintroduced)
DC's Stop Discrimination by Algorithms Act would bar algorithmic decision-making that discriminates in housing, employment, education, credit, healthcare, insurance. Mandates annual bias audits, consumer notice, disclosure; private right of action with civil penalties up to $10,000 per violation. Pending across DC Council sessions since 2021.
-
Proposed / pending
NYC Int 1003-2024
New York, NY · NYC Int 1003-2024
NYC Int 1003-2024 would amend the admin code to create an AI working group at the Commission on Human Rights to study AI's impact on employment and AEDT effects on protected classes — complementing Local Law 144.
-
Proposed / pending
NYC Int 1196-2025
New York, NY · NYC Int 1196-2025
NYC Int 1196-2025 proposes to amend the administrative code of the City of New York to prohibit the unauthorized depiction of public officials by artificial intelligence; it is not about additional requirements on city agencies' use of AI tools.
-
Proposed / pending
DC SDAA (B25-0114)
Washington, DC · D.C. Council B25-0114 (proposed)
A DC Council bill that would ban using algorithms to discriminate based on race, sex, age, or disability in important life decisions such as employment, housing, credit, insurance, and education, and would require notice and audits.
-
Proposed / pending
Orange County FL Public Schools
Orlando, FL · Orange County FL Public Schools — Draft AI Policy (2026-05-13)
Draft policy for SY 26-27 restricts use to ChatGPT, Gemini, Copilot, Adobe Firefly, Khanmigo in closed configurations; bars deepfakes, requires original wording, verification, and human-in-the-loop.
-
Proposed / pending
Chicago City AI Ordinance (stalled)
Chicago, IL · Chicago, Ill., Ordinance O2024-0008864 (pending in committee)
A pending Chicago ordinance would set citywide guidelines for how city government adopts AI tools in areas like traffic analysis, public safety, and waste management, create a pilot program, and require semi-annual public reports on the city's AI use. It has sat in committee since April 2024 without a vote.
-
Proposed / pending
NYC AI Oversight Office Bill
New York City, NY · N.Y.C. Council Int. No. 0919-2026 (pending)
A pending New York City Council bill would write an office of artificial intelligence oversight into the City Charter and Administrative Code, building on the city's 2025 GUARD Act package on algorithmic accountability for city agencies. Awaiting committee action.
-
Repealed / replaced
NYC LL144 (original draft)
New York City, NY · NYC Int. 1894-2020 (original) — narrowed before enactment as Local Law 144 of 2021
NYC's original Int. 1894-2020 draft was substantially broader than the enacted Local Law 144. The narrowed final version took effect January 1, 2023 (DCWP enforcement began July 5, 2023 after final rules) and is the most-cited city AI law globally — original-vs-enacted scope shift is studied widely.
-
Expired
DC Algorithm Bill (not enacted)
Washington, DC · D.C. Council B24-0558 (2021); B25-0114 (2023) (not enacted)
A proposed DC law that would ban businesses from using algorithms that discriminate based on protected traits in decisions about jobs, housing, credit, insurance, and education, and would require annual bias audits and consumer disclosures. Despite multiple introductions since 2021, it has never been enacted — DC residents rely on federal protections.